SYNOPSIS
nvme [<global-options>] keys gen-kxchap-secret [--hmac=<hmac-id> | -m <hmac-id>]
[--secret=<secret> | -s <secret>]
[--secret-length=<len> | -l <len>]
DESCRIPTION
Generate a KX-HMAC-CHAP secret in the DHHC-1 secret representation defined by the NVM Express Base Specification 2.4, section 8.3.4.5.8, in the form: DHHC-1:00:ia6zGodOr4SEG0Zzaw398rpY0wqipUWj4jWjUh4HWUz6aQ2n: and prints it to stdout.
OPTIONS
- -m <hmac-id>
- --hmac=<hmac-id>
-
Select the hash function the consumer is to apply to the secret. Possible values are: 0 - No transformation (the secret is used as the key) 1 - SHA-256 2 - SHA-384 3 - SHA-512
- -s <secret>
- --secret=<secret>
-
Secret value (in hexadecimal) to be placed in the representation. If none are provided a random value is used.
- -l <len>
- --secret-length=<len>
-
Length of the secret. Possible values are 32, 48, or 64. A secret given with --secret as hexadecimal fixes the length, so a value contradicting it is an error; a secret generated here takes this length, defaulting to the digest size of the selected hash function, or 32 if none is selected.
GLOBAL OPTIONS
The following options are defined at the top-level nvme command
and are available to this subcommand:
- --dry-run
-
Print the command that would be executed, but do not actually execute it.
- --no-ioctl-probing
-
Disable probing for 64-bit IOCTL support.
- --no-retries
-
Disable retry logic on transient errors.
- -o <fmt>
- --output-format=<fmt>
-
Set the reporting format to normal, tabular, 'json, or binary. Only one output format may be used at a time.
- --output-format-version=<version>
-
Select the output format version. Version 1 uses the original field naming, while version 2 (default) provides more consistent and script-friendly field names.
- --timeout=<ms>
-
Set the timeout for the command in milliseconds.
- -v
- --verbose
-
Increase the level of detail in the output. May be specified multiple times to further increase verbosity.
These options can also be set as machine-wide defaults in nvme-cli.conf(5). A command-line flag always overrides the file.
EXAMPLES
No Examples
NVME
Part of the nvme-user suite