'\" t
.\" Title: nvme-gen-tls-key
.\" Author: [FIXME: author] [see http://www.docbook.org/tdg5/en/html/author]
.\" Generator: DocBook XSL Stylesheets vsnapshot
.\" Date: 09/18/2026
.\" Manual: NVMe Manual
.\" Source: NVMe
.\" Language: English
.\"
.TH "NVME\-GEN\-TLS\-KEY" "1" "09/18/2026" "NVMe" "NVMe Manual"
.\" -----------------------------------------------------------------
.\" * Define some portability stuff
.\" -----------------------------------------------------------------
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.\" http://bugs.debian.org/507673
.\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.ie \n(.g .ds Aq \(aq
.el .ds Aq '
.\" -----------------------------------------------------------------
.\" * set default formatting
.\" -----------------------------------------------------------------
.\" disable hyphenation
.nh
.\" disable justification (adjust text to left margin only)
.ad l
.\" -----------------------------------------------------------------
.\" * MAIN CONTENT STARTS HERE *
.\" -----------------------------------------------------------------
.SH "NAME"
nvme-gen-tls-key \- Generate a NVMe TLS PSK (deprecated)
.SH "SYNOPSIS"
.sp
.nf
\fInvme\fR [] \fIgen\-tls\-key\fR [\-\-keyring= | \-k ]
[\-\-keytype= | \-t ]
[\-\-hostnqn= | \-n ]
[\-\-subsysnqn= | \-c ]
[\-\-hmac= | \-m ]
[\-\-identity= | \-I ]
[\-\-secret= | \-s ]
[\-\-insert | \-i]
[\-\-compat | \-C]
[\-\-keyfile= | \-f ]
.fi
.SH "DESCRIPTION"
.sp
Deprecated alias for \fBnvme-keys-gen-tls-psk\fR(1), kept for scripts written against nvme\-cli versions older than 3\&.0, with three differences from nvme\-cli 2\&.x:
.sp
.RS 4
.ie n \{\
\h'-04'\(bu\h'+03'\c
.\}
.el \{\
.sp -1
.IP \(bu 2.3
.\}
\fI\-\-insert\fR/\fI\-i\fR
reports
\fIInserted TLS PSK \fR
where 2\&.x said
\fIInserted TLS key \fR\&. A script matching the old wording needs updating\&.
.RE
.sp
.RS 4
.ie n \{\
\h'-04'\(bu\h'+03'\c
.\}
.el \{\
.sp -1
.IP \(bu 2.3
.\}
A
\fI\-\-secret\fR
with an odd number of hexadecimal characters is rejected\&. 2\&.x padded the trailing character with a zero and emitted a secret that was never given, the same behaviour
\fBnvme-gen-dhchap-key\fR(1)
had\&.
.RE
.sp
.RS 4
.ie n \{\
\h'-04'\(bu\h'+03'\c
.\}
.el \{\
.sp -1
.IP \(bu 2.3
.\}
The diagnostics that validate
\fI\-\-secret\fR
go to stdout, where 2\&.x put them on stderr\&. Most of them accompany a non\-zero exit, but
\fISkipping excess secret bytes\fR
does not: an over\-long
\fI\-\-secret\fR
still exits 0, with the warning sitting on stdout ahead of the key, so a script reading the key off stdout gets the warning instead\&.
.RE
.sp
New scripts should use \fInvme keys gen\-tls\-psk\fR instead\&. This alias prints a deprecation warning on stderr and may be removed in a future release\&.
.sp
See \fBnvme-keys-gen-tls-psk\fR(1) for the full option reference\&.
.SH "GLOBAL OPTIONS"
.sp
The following options are defined at the top\-level nvme command and are available to this subcommand:
.PP
\-\-dry\-run
.RS 4
Print the command that would be executed, but do not actually execute it\&.
.RE
.PP
\-\-no\-ioctl\-probing
.RS 4
Disable probing for 64\-bit IOCTL support\&.
.RE
.PP
\-\-no\-retries
.RS 4
Disable retry logic on transient errors\&.
.RE
.PP
\-o , \-\-output\-format=
.RS 4
Set the reporting format to
\fInormal\fR,
\fItabular, \*(Aqjson\fR, or
\fIbinary\fR\&. Only one output format may be used at a time\&.
.RE
.PP
\-\-output\-format\-version=
.RS 4
Select the output format version\&. Version
\fI1\fR
uses the original field naming, while version
\fI2\fR
(default) provides more consistent and script\-friendly field names\&.
.RE
.PP
\-\-timeout=
.RS 4
Set the timeout for the command in milliseconds\&.
.RE
.PP
\-v, \-\-verbose
.RS 4
Increase the level of detail in the output\&. May be specified multiple times to further increase verbosity\&.
.RE
.sp
These options can also be set as machine\-wide defaults in nvme\-cli\&.conf(5)\&. A command\-line flag always overrides the file\&.
.SH "EXAMPLES"
.sp
No Examples
.SH "NVME"
.sp
Part of the nvme\-user suite
.SH "SEE ALSO"
.sp
\fBnvme-keys-gen-tls-psk\fR(1)