---
title: KeyStoreSecretStore
description: Resource path:
component: pingam
version: 8
page_id: pingam:entity-reference:sec-amster-entity-keystoresecretstore
canonical_url: https://docs.pingidentity.com/pingam/8.1/entity-reference/sec-amster-entity-keystoresecretstore.html
llms_txt: https://docs.pingidentity.com/pingam/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
superseded_by: https://docs.pingidentity.com/pingam/8.1/entity-reference/sec-amster-entity-keystoresecretstore.html
section_ids:
  sec-amster-entity-keystoresecretstore-realm-ops: Realm Operations
  sec-amster-entity-keystoresecretstore-realm-ops-create: create
  sec-amster-entity-keystoresecretstore-realm-ops-delete: delete
  sec-amster-entity-keystoresecretstore-realm-ops-getalltypes: getAllTypes
  sec-amster-entity-keystoresecretstore-realm-ops-getcreatabletypes: getCreatableTypes
  sec-amster-entity-keystoresecretstore-realm-ops-nextdescendents: nextdescendents
  sec-amster-entity-keystoresecretstore-realm-ops-query: query
  sec-amster-entity-keystoresecretstore-realm-ops-read: read
  sec-amster-entity-keystoresecretstore-realm-ops-update: update
  sec-amster-entity-keystoresecretstore-global-ops: Global Operations
  sec-amster-entity-keystoresecretstore-global-ops-create: create
  sec-amster-entity-keystoresecretstore-global-ops-delete: delete
  sec-amster-entity-keystoresecretstore-global-ops-getalltypes: getAllTypes
  sec-amster-entity-keystoresecretstore-global-ops-getcreatabletypes: getCreatableTypes
  sec-amster-entity-keystoresecretstore-global-ops-nextdescendents: nextdescendents
  sec-amster-entity-keystoresecretstore-global-ops-query: query
  sec-amster-entity-keystoresecretstore-global-ops-read: read
  sec-amster-entity-keystoresecretstore-global-ops-update: update
---

# KeyStoreSecretStore

## Realm Operations

Resource path:

```
/realm-config/secrets/stores/KeyStoreSecretStore
```

Resource version: `2.0`

### create

**Usage**

```
am> create KeyStoreSecretStore --realm Realm --id id --body body
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

* *\--body*

  The resource in JSON format, described by the following JSON schema:

  ```json
  {
    "type" : "object",
    "properties" : {
      "leaseExpiryDuration" : {
        "title" : "Key lease expiry",
        "description" : "The amount of minutes a key can be cached from the keystore before it needs to be reloaded.",
        "propertyOrder" : 600,
        "required" : true,
        "type" : "integer",
        "exampleValue" : ""
      },
      "storePassword" : {
        "title" : "Store password secret label",
        "description" : "The secret label from which the store password can be obtained, or none if the password is blank. This secret label will be resolved using one of the other secret stores configured.<br> It must not start or end with the <code>.</code> character <br>The <code>.</code> character must not be followed by another <code>.</code> character.<br>Must contain <code>a-z</code>, <code>A-Z</code>, <code>0-9</code> and <code>.</code> characters only.",
        "propertyOrder" : 400,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      },
      "keyEntryPassword" : {
        "title" : "Entry password secret label",
        "description" : "The secret value from which the entry password can be obtained, or none if the password is blank. This secret label will be resolved using one of the other secret stores configured.<br> It must not start or end with the <code>.</code> character. <br>The <code>.</code> character must not be followed by another <code>.</code> character.<br>Must contain <code>a-z</code>, <code>A-Z</code>, <code>0-9</code> and <code>.</code> characters only.",
        "propertyOrder" : 500,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      },
      "file" : {
        "title" : "File",
        "description" : "The keystore file to use",
        "propertyOrder" : 100,
        "required" : true,
        "type" : "string",
        "exampleValue" : ""
      },
      "storetype" : {
        "title" : "Keystore type",
        "description" : "The type of the keystore (JKS, JCEKS, PKCS11, PKCS12, BCFKS, others). This must be a keystore type known or configured on the JRE.",
        "propertyOrder" : 200,
        "required" : true,
        "type" : "string",
        "exampleValue" : ""
      },
      "providerName" : {
        "title" : "Provider name",
        "description" : "The classname of a provider to use to load the keystore. If blank, the JRE default will be used.",
        "propertyOrder" : 300,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      }
    }
  }
  ```

### delete

**Usage**

```
am> delete KeyStoreSecretStore --realm Realm --id id
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

### getAllTypes

Obtain the collection of all secondary configuration types related to the resource.

**Usage**

```
am> action KeyStoreSecretStore --realm Realm --actionName getAllTypes
```

### getCreatableTypes

Obtain the collection of secondary configuration types that have yet to be added to the resource.

**Usage**

```
am> action KeyStoreSecretStore --realm Realm --actionName getCreatableTypes
```

### nextdescendents

Obtain the collection of secondary configuration instances that have been added to the resource.

**Usage**

```
am> action KeyStoreSecretStore --realm Realm --actionName nextdescendents
```

### query

Get the full list of instances of this collection. This query only supports `_queryFilter=true` filter.

**Usage**

```
am> query KeyStoreSecretStore --realm Realm --filter filter
```

**Parameters**

* *\--filter*

  A CREST formatted query filter, where "true" will query all.

### read

**Usage**

```
am> read KeyStoreSecretStore --realm Realm --id id
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

### update

**Usage**

```
am> update KeyStoreSecretStore --realm Realm --id id --body body
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

* *\--body*

  The resource in JSON format, described by the following JSON schema:

  ```json
  {
    "type" : "object",
    "properties" : {
      "leaseExpiryDuration" : {
        "title" : "Key lease expiry",
        "description" : "The amount of minutes a key can be cached from the keystore before it needs to be reloaded.",
        "propertyOrder" : 600,
        "required" : true,
        "type" : "integer",
        "exampleValue" : ""
      },
      "storePassword" : {
        "title" : "Store password secret label",
        "description" : "The secret label from which the store password can be obtained, or none if the password is blank. This secret label will be resolved using one of the other secret stores configured.<br> It must not start or end with the <code>.</code> character <br>The <code>.</code> character must not be followed by another <code>.</code> character.<br>Must contain <code>a-z</code>, <code>A-Z</code>, <code>0-9</code> and <code>.</code> characters only.",
        "propertyOrder" : 400,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      },
      "keyEntryPassword" : {
        "title" : "Entry password secret label",
        "description" : "The secret value from which the entry password can be obtained, or none if the password is blank. This secret label will be resolved using one of the other secret stores configured.<br> It must not start or end with the <code>.</code> character. <br>The <code>.</code> character must not be followed by another <code>.</code> character.<br>Must contain <code>a-z</code>, <code>A-Z</code>, <code>0-9</code> and <code>.</code> characters only.",
        "propertyOrder" : 500,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      },
      "file" : {
        "title" : "File",
        "description" : "The keystore file to use",
        "propertyOrder" : 100,
        "required" : true,
        "type" : "string",
        "exampleValue" : ""
      },
      "storetype" : {
        "title" : "Keystore type",
        "description" : "The type of the keystore (JKS, JCEKS, PKCS11, PKCS12, BCFKS, others). This must be a keystore type known or configured on the JRE.",
        "propertyOrder" : 200,
        "required" : true,
        "type" : "string",
        "exampleValue" : ""
      },
      "providerName" : {
        "title" : "Provider name",
        "description" : "The classname of a provider to use to load the keystore. If blank, the JRE default will be used.",
        "propertyOrder" : 300,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      }
    }
  }
  ```

## Global Operations

Resource path:

```
/global-config/secrets/stores/KeyStoreSecretStore
```

Resource version: `1.0`

### create

**Usage**

```
am> create KeyStoreSecretStore --global --id id --body body
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

* *\--body*

  The resource in JSON format, described by the following JSON schema:

  ```json
  {
    "type" : "object",
    "properties" : {
      "file" : {
        "title" : "File",
        "description" : "The keystore file to use",
        "propertyOrder" : 100,
        "required" : true,
        "type" : "string",
        "exampleValue" : ""
      },
      "storePassword" : {
        "title" : "Store password secret label",
        "description" : "The secret label from which the store password can be obtained, or none if the password is blank. This secret label will be resolved using one of the other secret stores configured.<br> It must not start or end with the <code>.</code> character <br>The <code>.</code> character must not be followed by another <code>.</code> character.<br>Must contain <code>a-z</code>, <code>A-Z</code>, <code>0-9</code> and <code>.</code> characters only.",
        "propertyOrder" : 400,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      },
      "keyEntryPassword" : {
        "title" : "Entry password secret label",
        "description" : "The secret value from which the entry password can be obtained, or none if the password is blank. This secret label will be resolved using one of the other secret stores configured.<br> It must not start or end with the <code>.</code> character. <br>The <code>.</code> character must not be followed by another <code>.</code> character.<br>Must contain <code>a-z</code>, <code>A-Z</code>, <code>0-9</code> and <code>.</code> characters only.",
        "propertyOrder" : 500,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      },
      "storetype" : {
        "title" : "Keystore type",
        "description" : "The type of the keystore (JKS, JCEKS, PKCS11, PKCS12, BCFKS, others). This must be a keystore type known or configured on the JRE.",
        "propertyOrder" : 200,
        "required" : true,
        "type" : "string",
        "exampleValue" : ""
      },
      "leaseExpiryDuration" : {
        "title" : "Key lease expiry",
        "description" : "The amount of minutes a key can be cached from the keystore before it needs to be reloaded.",
        "propertyOrder" : 600,
        "required" : true,
        "type" : "integer",
        "exampleValue" : ""
      },
      "providerName" : {
        "title" : "Provider name",
        "description" : "The classname of a provider to use to load the keystore. If blank, the JRE default will be used.",
        "propertyOrder" : 300,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      }
    }
  }
  ```

### delete

**Usage**

```
am> delete KeyStoreSecretStore --global --id id
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

### getAllTypes

Obtain the collection of all secondary configuration types related to the resource.

**Usage**

```
am> action KeyStoreSecretStore --global --actionName getAllTypes
```

### getCreatableTypes

Obtain the collection of secondary configuration types that have yet to be added to the resource.

**Usage**

```
am> action KeyStoreSecretStore --global --actionName getCreatableTypes
```

### nextdescendents

Obtain the collection of secondary configuration instances that have been added to the resource.

**Usage**

```
am> action KeyStoreSecretStore --global --actionName nextdescendents
```

### query

Get the full list of instances of this collection. This query only supports `_queryFilter=true` filter.

**Usage**

```
am> query KeyStoreSecretStore --global --filter filter
```

**Parameters**

* *\--filter*

  A CREST formatted query filter, where "true" will query all.

### read

**Usage**

```
am> read KeyStoreSecretStore --global --id id
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

### update

**Usage**

```
am> update KeyStoreSecretStore --global --id id --body body
```

**Parameters**

* *\--id*

  The unique identifier for the resource.

* *\--body*

  The resource in JSON format, described by the following JSON schema:

  ```json
  {
    "type" : "object",
    "properties" : {
      "file" : {
        "title" : "File",
        "description" : "The keystore file to use",
        "propertyOrder" : 100,
        "required" : true,
        "type" : "string",
        "exampleValue" : ""
      },
      "storePassword" : {
        "title" : "Store password secret label",
        "description" : "The secret label from which the store password can be obtained, or none if the password is blank. This secret label will be resolved using one of the other secret stores configured.<br> It must not start or end with the <code>.</code> character <br>The <code>.</code> character must not be followed by another <code>.</code> character.<br>Must contain <code>a-z</code>, <code>A-Z</code>, <code>0-9</code> and <code>.</code> characters only.",
        "propertyOrder" : 400,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      },
      "keyEntryPassword" : {
        "title" : "Entry password secret label",
        "description" : "The secret value from which the entry password can be obtained, or none if the password is blank. This secret label will be resolved using one of the other secret stores configured.<br> It must not start or end with the <code>.</code> character. <br>The <code>.</code> character must not be followed by another <code>.</code> character.<br>Must contain <code>a-z</code>, <code>A-Z</code>, <code>0-9</code> and <code>.</code> characters only.",
        "propertyOrder" : 500,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      },
      "storetype" : {
        "title" : "Keystore type",
        "description" : "The type of the keystore (JKS, JCEKS, PKCS11, PKCS12, BCFKS, others). This must be a keystore type known or configured on the JRE.",
        "propertyOrder" : 200,
        "required" : true,
        "type" : "string",
        "exampleValue" : ""
      },
      "leaseExpiryDuration" : {
        "title" : "Key lease expiry",
        "description" : "The amount of minutes a key can be cached from the keystore before it needs to be reloaded.",
        "propertyOrder" : 600,
        "required" : true,
        "type" : "integer",
        "exampleValue" : ""
      },
      "providerName" : {
        "title" : "Provider name",
        "description" : "The classname of a provider to use to load the keystore. If blank, the JRE default will be used.",
        "propertyOrder" : 300,
        "required" : false,
        "type" : "string",
        "exampleValue" : ""
      }
    }
  }
  ```
