1.\" Copyright (c) 2014 The FreeBSD Foundation 2.\" All rights reserved. 3.\" 4.\" This software was developed by Edward Tomasz Napierala under sponsorship 5.\" from the FreeBSD Foundation. 6.\" 7.\" Redistribution and use in source and binary forms, with or without 8.\" modification, are permitted provided that the following conditions 9.\" are met: 10.\" 1. Redistributions of source code must retain the above copyright 11.\" notice, this list of conditions and the following disclaimer. 12.\" 2. Redistributions in binary form must reproduce the above copyright 13.\" notice, this list of conditions and the following disclaimer in the 14.\" documentation and/or other materials provided with the distribution. 15.\" 16.\" THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND 17.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 18.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 19.\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE LIABLE 20.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 21.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 22.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 23.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 24.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 25.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 26.\" SUCH DAMAGE. 27.\" 28.\" $FreeBSD$ 29.\" 30.Dd December 10, 2014 31.Dt UEFISIGN 8 32.Os 33.Sh NAME 34.Nm uefisign 35.Nd UEFI Secure Boot signing utility 36.Sh SYNOPSIS 37.Nm 38.Fl k Ar key 39.Fl c Ar certificate 40.Fl o Ar output 41.Op Fl v 42.Ar file 43.Nm 44.Fl V 45.Op Fl v 46.Ar file 47.Sh DESCRIPTION 48The 49.Nm 50utility signs PE binary files using Authenticode scheme, as required by 51UEFI Secure Boot specification. 52Alternatively, it can be used to view and verify existing signatures. 53These options are available: 54.Bl -tag -width ".Fl l" 55.It Fl V 56Determine whether the file is signed. 57Note that this does not verify the correctness of the signature; 58only that the file contains a signature. 59.It Fl k 60Name of file containing the private key used to sign the binary. 61.It Fl c 62Name of file containing the certificate used to sign the binary. 63.It Fl o 64Name of file to write the signed binary to. 65.It Fl v 66Be verbose. 67.El 68.Sh EXIT STATUS 69The 70.Nm 71utility exits 0 on success, and >0 if an error occurs. 72.Sh EXAMPLES 73Generate self-signed certificate and use it to sign a binary: 74.Dl /usr/share/examples/uefisign/uefikeys testcert 75.Dl uefisign -c testcert.pem -k testcert.key -o signed-binary binary 76.Pp 77View signature: 78.Dl uefisign -Vv binary 79.Sh SEE ALSO 80.Xr openssl 1 , 81.Xr loader 8 , 82.Xr uefi 8 83.Sh HISTORY 84The 85.Nm 86command appeared in 87.Fx 11.0 . 88.Sh AUTHORS 89The 90.Nm 91utility was developed by 92.An Edward Tomasz Napierala Aq Mt trasz@FreeBSD.org 93under sponsorship from the FreeBSD Foundation. 94