DOKK / manpages / debian 12 / sbsigntool / sbsign.1.en
SBSIGN(1) User Commands SBSIGN(1)

sbsign - UEFI secure boot signing tool

sbsign [options] --key <keyfile> --cert <certfile> <efi-boot-image>

Sign an EFI boot image for use with secure boot.

use the specified engine to load the key
signing key (PEM-encoded RSA private key)
certificate (x509 certificate)

--addcert <addcertfile> additional intermediate certificates in a file

write a detached signature, instead of a signed binary
write signed data to <file> (default <efi-boot-image>.signed, or <efi-boot-image>.pk7 for detached signatures)
June 2022 sbsign 0.9.4