| NVME-KEYS-EXPORT(1) | NVMe Manual | NVME-KEYS-EXPORT(1) |
NAME
nvme-keys-export - Export NVMe TLS PSKs from a keyring
SYNOPSIS
nvme [<global-options>] keys export [--keyring=<name> | -k <name>]
[--keyfile=<file> | -f <file>]
DESCRIPTION
Export all NVMe TLS pre-shared keys (PSKs) from the system keyring in the form
<identity> <psk>
where <identity> is the TLS PSK identity the key is stored under and <psk> is the TLS PSK itself in PSK interchange format NVMeTLSkey-1:<hmac>:<base64 encoded data>:. Each key is exported in a single line.
The PSK interchange format otherwise carries a configured PSK: it is what nvme-keys-gen-tls-psk(1) prints and what nvme-keys-insert-tls-psk(1) and nvme-keys-check-tls-psk(1) read. The keys exported here are TLS PSKs instead. This output is meant for nvme-keys-import(1), which stores each key back under its identity unchanged; it is not intended to be passed to nvme-keys-insert-tls-psk(1) or nvme-keys-check-tls-psk(1).
OPTIONS
-k <name>, --keyring=<name>
-f <file>, --keyfile=<file>
GLOBAL OPTIONS
The following options are defined at the top-level nvme command and are available to this subcommand:
--dry-run
--no-ioctl-probing
--no-retries
-o <fmt>, --output-format=<fmt>
--output-format-version=<version>
--timeout=<ms>
-v, --verbose
These options can also be set as machine-wide defaults in nvme-cli.conf(5). A command-line flag always overrides the file.
EXAMPLES
# nvme keys export -f nvme-tls-keys.txt
# nvme keys export NVMe0R01 hostnqn0 subsys0 NVMeTLSkey-1:01:/b9tVz2OXJVISnoFgrPAygyS86XYJWkAapQeULns6PMpM8wv: # keyctl show Session Keyring 573249525 --alswrv 0 0 keyring: _ses 353599402 --alswrv 0 65534 \_ keyring: _uid.0 475911922 ---lswrv 0 0 \_ keyring: .nvme 649274894 --als-rv 0 0 \_ psk: NVMe0R01 hostnqn0 subsys0
NVME
Part of the nvme-user suite
| 09/07/2026 | NVMe |