'\" t
.\" Title: nvme-keys-import
.\" Author: [FIXME: author] [see http://www.docbook.org/tdg5/en/html/author]
.\" Generator: DocBook XSL Stylesheets vsnapshot
.\" Date: 09/07/2026
.\" Manual: NVMe Manual
.\" Source: NVMe
.\" Language: English
.\"
.TH "NVME\-KEYS\-IMPORT" "1" "09/07/2026" "NVMe" "NVMe Manual"
.\" -----------------------------------------------------------------
.\" * Define some portability stuff
.\" -----------------------------------------------------------------
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.\" http://bugs.debian.org/507673
.\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.ie \n(.g .ds Aq \(aq
.el .ds Aq '
.\" -----------------------------------------------------------------
.\" * set default formatting
.\" -----------------------------------------------------------------
.\" disable hyphenation
.nh
.\" disable justification (adjust text to left margin only)
.ad l
.\" -----------------------------------------------------------------
.\" * MAIN CONTENT STARTS HERE *
.\" -----------------------------------------------------------------
.SH "NAME"
nvme-keys-import \- Import NVMeoF TLS PSKs or KX\-HMAC\-CHAP secrets into a keyring
.SH "SYNOPSIS"
.sp
.nf
\fInvme\fR [] \fIkeys import\fR [\-\-keyring= | \-k ]
[\-\-keyfile= | \-f ]
[\-\-keydata= | \-d ]
[\-\-identity= | \-i ]
.fi
.SH "DESCRIPTION"
.sp
Imports one or more already\-identified keys into a keyring\&. The key type (NVMe TLS PSK or KX\-HMAC\-CHAP host secret) is auto\-detected from the key\(cqs prefix (\fINVMeTLSkey\-1:\fR or \fIDHHC\-1:\fR)\&.
.sp
Without \fI\-\-identity\fR, keys are read in bulk\&. Key data is read in the form
.sp
.sp
where \fI\fR is the key description \(em the TLS PSK identity for a TLS PSK \(em and \fI\fR is either a TLS PSK in interchange format \fINVMeTLSkey\-1:::\fR or a KX\-HMAC\-CHAP secret in the form \fIDHHC\-1:::\fR, one key per line, and imported into the kernel keyring\&. This is the format produced by \fBnvme-keys-export\fR(1)\&.
.sp
With \fI\-\-identity\fR, a single key is imported instead: the key is read from \fI\-\-keydata\fR (or, if not given, from stdin) and stored under the given identity\&. This is the way to insert a single KX\-HMAC\-CHAP secret, or a previously derived TLS PSK, directly by identity, without needing a keyfile\&.
.sp
Note that this command does not derive a TLS PSK from a configured PSK, nor compute the identity to store it under from a host/subsystem NQN pair; use \fBnvme-keys-insert-tls-psk\fR(1) for that\&.
.SH "OPTIONS"
.PP
\-k , \-\-keyring=
.RS 4
Name of the keyring to import the keys into\&. Default is
\fI\&.nvme\fR\&.
.RE
.PP
\-f , \-\-keyfile=
.RS 4
File to read the keys from instead of stdin\&. Only used in bulk mode (i\&.e\&. when
\fI\-\-identity\fR
is not given)\&.
.RE
.PP
\-d , \-\-keydata=
.RS 4
Key to be inserted when
\fI\-\-identity\fR
is given\&. If not given, the key is read from stdin\&.
.RE
.PP
\-i , \-\-identity=
.RS 4
Identity to store a single key under\&. If given,
\fI\-\-keydata\fR
(or stdin) is read as a single key instead of a bulk list\&.
.RE
.SH "GLOBAL OPTIONS"
.sp
The following options are defined at the top\-level nvme command and are available to this subcommand:
.PP
\-\-dry\-run
.RS 4
Print the command that would be executed, but do not actually execute it\&.
.RE
.PP
\-\-no\-ioctl\-probing
.RS 4
Disable probing for 64\-bit IOCTL support\&.
.RE
.PP
\-\-no\-retries
.RS 4
Disable retry logic on transient errors\&.
.RE
.PP
\-o , \-\-output\-format=
.RS 4
Set the reporting format to
\fInormal\fR,
\fItabular, \*(Aqjson\fR, or
\fIbinary\fR\&. Only one output format may be used at a time\&.
.RE
.PP
\-\-output\-format\-version=
.RS 4
Select the output format version\&. Version
\fI1\fR
uses the original field naming, while version
\fI2\fR
(default) provides more consistent and script\-friendly field names\&.
.RE
.PP
\-\-timeout=
.RS 4
Set the timeout for the command in milliseconds\&.
.RE
.PP
\-v, \-\-verbose
.RS 4
Increase the level of detail in the output\&. May be specified multiple times to further increase verbosity\&.
.RE
.sp
These options can also be set as machine\-wide defaults in nvme\-cli\&.conf(5)\&. A command\-line flag always overrides the file\&.
.SH "EXAMPLES"
.sp
.RS 4
.ie n \{\
\h'-04'\(bu\h'+03'\c
.\}
.el \{\
.sp -1
.IP \(bu 2.3
.\}
Import previously exported keys from a file and verify with keyctl
.sp
.if n \{\
.RS 4
.\}
.nf
# nvme keys import \-f nvme\-tls\-keys\&.txt
# keyctl show
Session Keyring
573249525 \-\-alswrv 0 0 keyring: _ses
353599402 \-\-alswrv 0 65534 \e_ keyring: _uid\&.0
475911922 \-\-\-lswrv 0 0 \e_ keyring: \&.nvme
734343968 \-\-als\-rv 0 0 \e_ psk: NVMe0R01 hostnqn0 subsys0
.fi
.if n \{\
.RE
.\}
.RE
.sp
.RS 4
.ie n \{\
\h'-04'\(bu\h'+03'\c
.\}
.el \{\
.sp -1
.IP \(bu 2.3
.\}
Import a single KX\-HMAC\-CHAP secret under an explicit identity
.sp
.if n \{\
.RS 4
.\}
.nf
# nvme keys import \-i host2 \-d DHHC\-1:00:ia6zGodOr4SEG0Zzaw398rpY0wqipUWj4jWjUh4HWUz6aQ2n:
.fi
.if n \{\
.RE
.\}
.RE
.SH "NVME"
.sp
Part of the nvme\-user suite