'\" t .\" Title: nvme-keys-export .\" Author: [FIXME: author] [see http://www.docbook.org/tdg5/en/html/author] .\" Generator: DocBook XSL Stylesheets vsnapshot .\" Date: 09/07/2026 .\" Manual: NVMe Manual .\" Source: NVMe .\" Language: English .\" .TH "NVME\-KEYS\-EXPORT" "1" "09/07/2026" "NVMe" "NVMe Manual" .\" ----------------------------------------------------------------- .\" * Define some portability stuff .\" ----------------------------------------------------------------- .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .\" http://bugs.debian.org/507673 .\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .ie \n(.g .ds Aq \(aq .el .ds Aq ' .\" ----------------------------------------------------------------- .\" * set default formatting .\" ----------------------------------------------------------------- .\" disable hyphenation .nh .\" disable justification (adjust text to left margin only) .ad l .\" ----------------------------------------------------------------- .\" * MAIN CONTENT STARTS HERE * .\" ----------------------------------------------------------------- .SH "NAME" nvme-keys-export \- Export NVMe TLS PSKs from a keyring .SH "SYNOPSIS" .sp .nf \fInvme\fR [] \fIkeys export\fR [\-\-keyring= | \-k ] [\-\-keyfile= | \-f ] .fi .SH "DESCRIPTION" .sp Export all NVMe TLS pre\-shared keys (PSKs) from the system keyring in the form .sp .sp where \fI\fR is the TLS PSK identity the key is stored under and \fI\fR is the TLS PSK itself in PSK interchange format \fINVMeTLSkey\-1:::\fR\&. Each key is exported in a single line\&. .sp The PSK interchange format otherwise carries a configured PSK: it is what \fBnvme-keys-gen-tls-psk\fR(1) prints and what \fBnvme-keys-insert-tls-psk\fR(1) and \fBnvme-keys-check-tls-psk\fR(1) read\&. The keys exported here are TLS PSKs instead\&. This output is meant for \fBnvme-keys-import\fR(1), which stores each key back under its identity unchanged; it is not intended to be passed to \fBnvme-keys-insert-tls-psk\fR(1) or \fBnvme-keys-check-tls-psk\fR(1)\&. .SH "OPTIONS" .PP \-k , \-\-keyring= .RS 4 Name of the keyring to export the TLS PSKs from\&. Default is \fI\&.nvme\fR\&. .RE .PP \-f , \-\-keyfile= .RS 4 File to write the exported keys to instead of stdout\&. .RE .SH "GLOBAL OPTIONS" .sp The following options are defined at the top\-level nvme command and are available to this subcommand: .PP \-\-dry\-run .RS 4 Print the command that would be executed, but do not actually execute it\&. .RE .PP \-\-no\-ioctl\-probing .RS 4 Disable probing for 64\-bit IOCTL support\&. .RE .PP \-\-no\-retries .RS 4 Disable retry logic on transient errors\&. .RE .PP \-o , \-\-output\-format= .RS 4 Set the reporting format to \fInormal\fR, \fItabular, \*(Aqjson\fR, or \fIbinary\fR\&. Only one output format may be used at a time\&. .RE .PP \-\-output\-format\-version= .RS 4 Select the output format version\&. Version \fI1\fR uses the original field naming, while version \fI2\fR (default) provides more consistent and script\-friendly field names\&. .RE .PP \-\-timeout= .RS 4 Set the timeout for the command in milliseconds\&. .RE .PP \-v, \-\-verbose .RS 4 Increase the level of detail in the output\&. May be specified multiple times to further increase verbosity\&. .RE .sp These options can also be set as machine\-wide defaults in nvme\-cli\&.conf(5)\&. A command\-line flag always overrides the file\&. .SH "EXAMPLES" .sp .RS 4 .ie n \{\ \h'-04'\(bu\h'+03'\c .\} .el \{\ .sp -1 .IP \(bu 2.3 .\} Export previously created keys from the kernel keyring and store them into a file .sp .if n \{\ .RS 4 .\} .nf # nvme keys export \-f nvme\-tls\-keys\&.txt .fi .if n \{\ .RE .\} .RE .sp .RS 4 .ie n \{\ \h'-04'\(bu\h'+03'\c .\} .el \{\ .sp -1 .IP \(bu 2.3 .\} Export/list all keys from the \&.nvme keyring using nvme and keyctl .sp .if n \{\ .RS 4 .\} .nf # nvme keys export NVMe0R01 hostnqn0 subsys0 NVMeTLSkey\-1:01:/b9tVz2OXJVISnoFgrPAygyS86XYJWkAapQeULns6PMpM8wv: # keyctl show Session Keyring 573249525 \-\-alswrv 0 0 keyring: _ses 353599402 \-\-alswrv 0 65534 \e_ keyring: _uid\&.0 475911922 \-\-\-lswrv 0 0 \e_ keyring: \&.nvme 649274894 \-\-als\-rv 0 0 \e_ psk: NVMe0R01 hostnqn0 subsys0 .fi .if n \{\ .RE .\} .RE .SH "NVME" .sp Part of the nvme\-user suite