SYNOPSIS

nvme [<global-options>] keys gen-kxchap-secret [--hmac=<hmac-id> | -m <hmac-id>]
                        [--secret=<secret> | -s <secret>]
                        [--secret-length=<len> | -l <len>]

DESCRIPTION

Generate a KX-HMAC-CHAP secret in the DHHC-1 secret representation defined by the NVM Express Base Specification 2.4, section 8.3.4.5.8, in the form: DHHC-1:00:ia6zGodOr4SEG0Zzaw398rpY0wqipUWj4jWjUh4HWUz6aQ2n: and prints it to stdout.

OPTIONS

-m <hmac-id>
--hmac=<hmac-id>

Select the hash function the consumer is to apply to the secret. Possible values are: 0 - No transformation (the secret is used as the key) 1 - SHA-256 2 - SHA-384 3 - SHA-512

-s <secret>
--secret=<secret>

Secret value (in hexadecimal) to be placed in the representation. If none are provided a random value is used.

-l <len>
--secret-length=<len>

Length of the secret. Possible values are 32, 48, or 64. A secret given with --secret as hexadecimal fixes the length, so a value contradicting it is an error; a secret generated here takes this length, defaulting to the digest size of the selected hash function, or 32 if none is selected.

GLOBAL OPTIONS

The following options are defined at the top-level nvme command and are available to this subcommand:

--dry-run

Print the command that would be executed, but do not actually execute it.

--no-ioctl-probing

Disable probing for 64-bit IOCTL support.

--no-retries

Disable retry logic on transient errors.

-o <fmt>
--output-format=<fmt>

Set the reporting format to normal, tabular, 'json, or binary. Only one output format may be used at a time.

--output-format-version=<version>

Select the output format version. Version 1 uses the original field naming, while version 2 (default) provides more consistent and script-friendly field names.

--timeout=<ms>

Set the timeout for the command in milliseconds.

-v
--verbose

Increase the level of detail in the output. May be specified multiple times to further increase verbosity.

These options can also be set as machine-wide defaults in nvme-cli.conf(5). A command-line flag always overrides the file.

EXAMPLES

No Examples

NVME

Part of the nvme-user suite