DOKK / manpages / debian 11 / sbsigntool / sbattach.1.en
SBATTACH(1) User Commands SBATTACH(1)

sbattach - UEFI secure boot detached signature tool

sbattach --attach <sigfile> <efi-boot-image>
sbattach --detach <sigfile> [--remove] <efi-boot-image>
sbattach --remove <efi-boot-image>

Attach or detach a signature file to/from a boot image

set <sigfile> as the boot image's signature table
copy the boot image's signature table to <sigfile>
remove the boot image's signature table from the original file
signature to operate on (defaults to first)
April 2019 sbattach 0.9.2