'\" t .\" Title: nvme-keys-import .\" Author: [FIXME: author] [see http://www.docbook.org/tdg5/en/html/author] .\" Generator: DocBook XSL Stylesheets vsnapshot .\" Date: 09/07/2026 .\" Manual: NVMe Manual .\" Source: NVMe .\" Language: English .\" .TH "NVME\-KEYS\-IMPORT" "1" "09/07/2026" "NVMe" "NVMe Manual" .\" ----------------------------------------------------------------- .\" * Define some portability stuff .\" ----------------------------------------------------------------- .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .\" http://bugs.debian.org/507673 .\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .ie \n(.g .ds Aq \(aq .el .ds Aq ' .\" ----------------------------------------------------------------- .\" * set default formatting .\" ----------------------------------------------------------------- .\" disable hyphenation .nh .\" disable justification (adjust text to left margin only) .ad l .\" ----------------------------------------------------------------- .\" * MAIN CONTENT STARTS HERE * .\" ----------------------------------------------------------------- .SH "NAME" nvme-keys-import \- Import NVMeoF TLS PSKs or KX\-HMAC\-CHAP secrets into a keyring .SH "SYNOPSIS" .sp .nf \fInvme\fR [] \fIkeys import\fR [\-\-keyring= | \-k ] [\-\-keyfile= | \-f ] [\-\-keydata= | \-d ] [\-\-identity= | \-i ] .fi .SH "DESCRIPTION" .sp Imports one or more already\-identified keys into a keyring\&. The key type (NVMe TLS PSK or KX\-HMAC\-CHAP host secret) is auto\-detected from the key\(cqs prefix (\fINVMeTLSkey\-1:\fR or \fIDHHC\-1:\fR)\&. .sp Without \fI\-\-identity\fR, keys are read in bulk\&. Key data is read in the form .sp .sp where \fI\fR is the key description \(em the TLS PSK identity for a TLS PSK \(em and \fI\fR is either a TLS PSK in interchange format \fINVMeTLSkey\-1:::\fR or a KX\-HMAC\-CHAP secret in the form \fIDHHC\-1:::\fR, one key per line, and imported into the kernel keyring\&. This is the format produced by \fBnvme-keys-export\fR(1)\&. .sp With \fI\-\-identity\fR, a single key is imported instead: the key is read from \fI\-\-keydata\fR (or, if not given, from stdin) and stored under the given identity\&. This is the way to insert a single KX\-HMAC\-CHAP secret, or a previously derived TLS PSK, directly by identity, without needing a keyfile\&. .sp Note that this command does not derive a TLS PSK from a configured PSK, nor compute the identity to store it under from a host/subsystem NQN pair; use \fBnvme-keys-insert-tls-psk\fR(1) for that\&. .SH "OPTIONS" .PP \-k , \-\-keyring= .RS 4 Name of the keyring to import the keys into\&. Default is \fI\&.nvme\fR\&. .RE .PP \-f , \-\-keyfile= .RS 4 File to read the keys from instead of stdin\&. Only used in bulk mode (i\&.e\&. when \fI\-\-identity\fR is not given)\&. .RE .PP \-d , \-\-keydata= .RS 4 Key to be inserted when \fI\-\-identity\fR is given\&. If not given, the key is read from stdin\&. .RE .PP \-i , \-\-identity= .RS 4 Identity to store a single key under\&. If given, \fI\-\-keydata\fR (or stdin) is read as a single key instead of a bulk list\&. .RE .SH "GLOBAL OPTIONS" .sp The following options are defined at the top\-level nvme command and are available to this subcommand: .PP \-\-dry\-run .RS 4 Print the command that would be executed, but do not actually execute it\&. .RE .PP \-\-no\-ioctl\-probing .RS 4 Disable probing for 64\-bit IOCTL support\&. .RE .PP \-\-no\-retries .RS 4 Disable retry logic on transient errors\&. .RE .PP \-o , \-\-output\-format= .RS 4 Set the reporting format to \fInormal\fR, \fItabular, \*(Aqjson\fR, or \fIbinary\fR\&. Only one output format may be used at a time\&. .RE .PP \-\-output\-format\-version= .RS 4 Select the output format version\&. Version \fI1\fR uses the original field naming, while version \fI2\fR (default) provides more consistent and script\-friendly field names\&. .RE .PP \-\-timeout= .RS 4 Set the timeout for the command in milliseconds\&. .RE .PP \-v, \-\-verbose .RS 4 Increase the level of detail in the output\&. May be specified multiple times to further increase verbosity\&. .RE .sp These options can also be set as machine\-wide defaults in nvme\-cli\&.conf(5)\&. A command\-line flag always overrides the file\&. .SH "EXAMPLES" .sp .RS 4 .ie n \{\ \h'-04'\(bu\h'+03'\c .\} .el \{\ .sp -1 .IP \(bu 2.3 .\} Import previously exported keys from a file and verify with keyctl .sp .if n \{\ .RS 4 .\} .nf # nvme keys import \-f nvme\-tls\-keys\&.txt # keyctl show Session Keyring 573249525 \-\-alswrv 0 0 keyring: _ses 353599402 \-\-alswrv 0 65534 \e_ keyring: _uid\&.0 475911922 \-\-\-lswrv 0 0 \e_ keyring: \&.nvme 734343968 \-\-als\-rv 0 0 \e_ psk: NVMe0R01 hostnqn0 subsys0 .fi .if n \{\ .RE .\} .RE .sp .RS 4 .ie n \{\ \h'-04'\(bu\h'+03'\c .\} .el \{\ .sp -1 .IP \(bu 2.3 .\} Import a single KX\-HMAC\-CHAP secret under an explicit identity .sp .if n \{\ .RS 4 .\} .nf # nvme keys import \-i host2 \-d DHHC\-1:00:ia6zGodOr4SEG0Zzaw398rpY0wqipUWj4jWjUh4HWUz6aQ2n: .fi .if n \{\ .RE .\} .RE .SH "NVME" .sp Part of the nvme\-user suite