SYNOPSIS

nvme [<global-options>] gen-tls-key [--keyring=<name> | -k <name>]
                        [--keytype=<type> | -t <type>]
                        [--hostnqn=<nqn> | -n <nqn>]
                        [--subsysnqn=<nqn> | -c <nqn>]
                        [--hmac=<hmac-id> | -m <hmac-id>]
                        [--identity=<id-vers> | -I <id-vers>]
                        [--secret=<secret> | -s <secret>]
                        [--insert | -i]
                        [--compat | -C]
                        [--keyfile=<keyfile> | -f <keyfile>]

DESCRIPTION

Deprecated alias for nvme-keys-gen-tls-psk(1), kept for scripts written against nvme-cli versions older than 3.0, with three differences from nvme-cli 2.x:

  • --insert/-i reports Inserted TLS PSK <serial> where 2.x said Inserted TLS key <serial>. A script matching the old wording needs updating.

  • A --secret with an odd number of hexadecimal characters is rejected. 2.x padded the trailing character with a zero and emitted a secret that was never given, the same behaviour nvme-gen-dhchap-key(1) had.

  • The diagnostics that validate --secret go to stdout, where 2.x put them on stderr. Most of them accompany a non-zero exit, but Skipping excess secret bytes does not: an over-long --secret still exits 0, with the warning sitting on stdout ahead of the key, so a script reading the key off stdout gets the warning instead.

New scripts should use nvme keys gen-tls-psk instead. This alias prints a deprecation warning on stderr and may be removed in a future release.

See nvme-keys-gen-tls-psk(1) for the full option reference.

GLOBAL OPTIONS

The following options are defined at the top-level nvme command and are available to this subcommand:

--dry-run

Print the command that would be executed, but do not actually execute it.

--no-ioctl-probing

Disable probing for 64-bit IOCTL support.

--no-retries

Disable retry logic on transient errors.

-o <fmt>
--output-format=<fmt>

Set the reporting format to normal, tabular, 'json, or binary. Only one output format may be used at a time.

--output-format-version=<version>

Select the output format version. Version 1 uses the original field naming, while version 2 (default) provides more consistent and script-friendly field names.

--timeout=<ms>

Set the timeout for the command in milliseconds.

-v
--verbose

Increase the level of detail in the output. May be specified multiple times to further increase verbosity.

These options can also be set as machine-wide defaults in nvme-cli.conf(5). A command-line flag always overrides the file.

EXAMPLES

No Examples

NVME

Part of the nvme-user suite

SEE ALSO