1PESIGN-CLIENT(1)            General Commands Manual           PESIGN-CLIENT(1)
2
3
4

NAME

6       pesign-client - command line tool for signing UEFI applications
7
8

SYNOPSIS

10       pesign [--in=infile | -i infile]
11              [--out=outfile | -o outfile]
12              [--export=exportfile | -e exportfile]
13              [--token=token | -t token]
14              [--certificate=nickname | -c nickname]
15              [--unlock | -u] [--kill | -k] [--sign | -s]
16              [--pinfd=pinfd | -f pinfd]
17              [--pinfile=pinfile | -F pinfile]
18
19

DESCRIPTION

21       pesign  is  a command line tool for manipulating signatures and crypto‐
22       graphic digests of UEFI applications.
23
24

OPTIONS

26       --unlock
27              Unlock the specified  token.   A  PIN  -  specified  by  one  of
28              --pinfd,    --pinfile,    or    the    environmental    variable
29              PESIGN_TOKEN_PIN - is required for this  operation  to  succeed.
30              The  PIN may be empty, if that is what is required for the token
31              specified with --token.
32
33
34       --pinfd=pinfd
35              When using --unlock, read the token's PIN  from  the  open  file
36              descriptor pinfd.
37
38
39       --pinfile=pinfile
40              When using --unlock, read the token's PIN from the file pinfile.
41
42
43       --sign
44              Sign the binary specified by infile.
45
46
47       --export
48              When used with --sign, write the signature to outfile.
49
50
51       --infile=infile
52              When used with --sign, specify the input binary.
53
54
55       --outfile=outfile
56              When  used  with  --sign, specify output file.  If --detached is
57              specified, this will be a DER-formatted  signature.   Otherwise,
58              the output will be the signed PE binary.
59
60
61       --token=token
62              When used with --unlock or --sign, use the specified NSS token's
63              certificate database.
64
65
66       --certificate=nickname
67              When used with --sign, use the certificate database  entry  with
68              the specified nickname for signing.
69
70
71       --kill
72              Terminate the signing server.
73
74

SEE ALSO

76       pesign(1)
77
78

AUTHORS

80       Peter Jones
81
82
83
84                                Mon Oct 15 2012               PESIGN-CLIENT(1)
Impressum