SYNOPSIS

nvme [<global-options>] rpmb program-key <device>
                        [--key=<key> | -k <key>]
                        [--keyfile=<key-file> | -g <key-file>]
                        [--target=<target-id> | -t <target-id>]

DESCRIPTION

Programs the given authentication key to the specified RPMB target. As per the RPMB specification, this is a one time action per target which cannot be undone.

The <device> parameter is mandatory and an NVMe character device (ex: /dev/nvme0) must be specified.

OPTIONS

-t <target>
--target=<target>

RPMB target id. This should be one of the supported RPMB targets as reported by nvme rpmb info. If nothing is given, the default of 0 is used as the RPMB target.

-k <key>
--key=<key>
-g <key-file>
--keyfile=<key-file>

Authentication key to program. The key can be specified on the command line using --key or -k, or read from a file using --keyfile or -g. The key size must be between 1 and 223 bytes.

GLOBAL OPTIONS

The following options are defined at the top-level nvme command and are available to this subcommand:

--dry-run

Print the command that would be executed, but do not actually execute it.

--no-ioctl-probing

Disable probing for 64-bit IOCTL support.

--no-retries

Disable retry logic on transient errors.

-o <fmt>
--output-format=<fmt>

Set the reporting format to normal, tabular, 'json, or binary. Only one output format may be used at a time.

--output-format-version=<version>

Select the output format version. Version 1 uses the original field naming, while version 2 (default) provides more consistent and script-friendly field names.

--timeout=<ms>

Set the timeout for the command in milliseconds.

-v
--verbose

Increase the level of detail in the output. May be specified multiple times to further increase verbosity.

These options can also be set as machine-wide defaults in nvme-cli.conf(5). A command-line flag always overrides the file.

EXAMPLES

  • Program SecretKey as authentication key for target 1

    # nvme rpmb program-key /dev/nvme0 --key='SecretKey' --target=1

NVME

Part of the nvme-user suite