DOKK / manpages / debian 10 / sbsigntool / sbvarsign.1.en
SBVARSIGN(1) User Commands SBVARSIGN(1)

sbvarsign - UEFI authenticated variable signing tool

sbvarsign [options] --key <keyfile> --cert <certfile> <var-name> <var-data-file>

Sign a blob of data for use in SetVariable().

use the specified engine to load the key
signing key (PEM-encoded RSA private key)
certificate (x509 certificate)
include attrs at beginning of output file
EFI GUID for the variable. If omitted, EFI_IMAGE_SECURITY_DATABASE or EFI_GLOBAL_VARIABLE (depending on <var-name>) will be used.
variable attributes. One or more of: NON_VOLATILE BOOTSERVICE_ACCESS RUNTIME_ACCESS TIME_BASED_AUTHENTICATED_WRITE_ACCESS APPEND_WRITE
default is all attributes, TIME_BASED_AUTH... is always included.
write signed data to <file> (default <var-data-file>.signed)
April 2019 sbvarsign 0.9.2