Creates a new user account with the <username> username. See below for the supported options.

For example, the code selects one of the Cryptographic Security Platform Vault nodes, logs in as secroot, lists the users and groups, and creates two new users.

$ hicli kc select kc-1
$ hicli kc
Current KeyControl: kc-1
$ hicli user login secroot
Password for secroot: ********
$ hicli user list
Username Full Name Privileges
---------------------------------------------------
secroot Security Administrator SEC_ADMIN,DOMAIN_ADMIN,CLOUD_ADMIN
$ hicli group list
Group Name Description Members
---------------------------------------------------
Cloud Admin Group Default Group for Administering Cloud VMs secroot
West-Cloud-Group Includes all West Coast Cloud VM Sets secroot
$ hicli user new spate --email=spate@me.com --password=Mypasswd236! \
--roles="SEC_ADMIN, DOMAIN_ADMIN, CLOUD_ADMIN" --full_name="Steve Pate" \
--groups="Cloud Admin Group, SF-Datacenter"
$ hicli user new mrogers --email=martha@me.com --password=Passwd123! \
--roles="CLOUD_ADMIN" --full_name="Martha Rogers" --groups="SF-Datacenter"
$ hicli user list
Username Full Name Privileges
---------------------------------------------------
mrogers Martha Rogers CLOUD_ADMIN
secroot Security Administrator SEC_ADMIN,DOMAIN_ADMIN,CLOUD_ADMIN
spate Steve Pate SEC_ADMIN,DOMAIN_ADMIN,CLOUD_ADMIN
$ hicli group list
Group Name Description Members
---------------------------------------------------
Cloud Admin Group Default Group for Administering Cloud VMs secroot,spate
West-Cloud-Group Includes all West Coast Cloud VM Sets secroot,spate,mrogers

email=<email>

The user email

password=<passwd>

The user password

full_name=<full_name>

The user password

authentication=<authentication>

The default authentication method: local or ldap. This option affects only newly-created user accounts. It does not change the authentication method for existing accounts.

account_state=<active|disabled>

The account state

roles=<privlist>

A comma-separated list of roles. Allowed roles are:

  • CLOUD_ADMIN
  • DOMAIN_ADMIN
  • SEC_ADMIN

groups=<grouplist>

A comma-separated list of the groups to which this user should belong. 

Each group name must be surrounded by double quotes. 

password_expiration=<date>

The date on which the selected user's password expires. 

The next time that user logs in, they will be prompted to set a new password.

account_expiration=<date>

The date on which the user account will be automatically disabled.

email=<email>

The user email

password=<passwd>

The user password

full_name=<full_name>

The user password

authentication=<authentication>

The default authentication method: local or ldap. 

This option affects only newly-created user accounts. It does not change the authentication method for existing accounts.

account_state=<active|disabled>

The account state

roles=<privlist>

A comma-separated list of roles. Allowed roles are:

  • CLOUD_ADMIN
  • DOMAIN_ADMIN
  • SEC_ADMIN

groups=<grouplist>

A comma-separated list of the groups to which this user should belong. 

Each group name must be surrounded by double quotes. 

password_expiration=<date>

The date on which the selected user's password expires. 

The next time that user logs in, they will be prompted to set a new password.

account_expiration=<date>

The date on which the user account will be automatically disabled.