.ie \n(.g .ds Aq \(aq .el .ds Aq ' .TH nethsm-user-untag 1 "nethsm-user-untag " .SH NAME nethsm\-user\-untag \- Remove a tag from a user .SH SYNOPSIS \fBnethsm user untag\fR [\fB\-a\fR|\fB\-\-auth\-passphrase\-file\fR] [\fB\-c\fR|\fB\-\-config\fR] [\fB\-l\fR|\fB\-\-label\fR] [\fB\-u\fR|\fB\-\-user\fR] [\fB\-h\fR|\fB\-\-help\fR] <\fINAME\fR> <\fITAG\fR> .SH DESCRIPTION Remove a tag from a user .PP Tags provide access to keys for users. Removing a tag from a user removes its access to keys that carry identical tags. .PP System\-wide users in the "Administrator" role can only remove tags for system\-wide users in the "Operator" role. Namespaced users in the "Administrator" role can only remove tags for users in the "Operator" role in the same namespace. .PP The device must be in state "Operational". .PP Requires authentication of a user in the "Administrator" role. .SH OPTIONS .TP \fB\-a\fR, \fB\-\-auth\-passphrase\-file\fR \fI\fR The path to a file containing a passphrase for authentication The passphrase provided in the file must be the one for the user chosen for the command. This option can be provided multiple times, which is needed for commands that require multiple roles at once. With multiple passphrase files ordering matters, as the files are assigned to the respective user provided by the "\-\-user" option. .RS May also be specified with the \fBNETHSM_AUTH_PASSPHRASE_FILE\fR environment variable. .RE .TP \fB\-c\fR, \fB\-\-config\fR \fI\fR The path to a custom configuration file If specified, the custom configuration file is used instead of the default configuration file location. .RS May also be specified with the \fBNETHSM_CONFIG\fR environment variable. .RE .TP \fB\-l\fR, \fB\-\-label\fR \fI