sbctl
A user-friendly secure boot key manager. Note: Not enrolling Microsoft's certificates can brick your system. See <https://github.com/Foxboron/sbctl/wiki/FAQ#option-rom>.
More info →Options (2)
-m, --microsoftbooleanEnroll the custom secure boot keys and Microsoft's UEFI vendor certificates
sbctl enroll-keys {{[-m|--microsoft]}}-s, --savebooleanSign an EFI binary with the created key and save the file to the database
sbctl sign {{[-s|--save]}} {{path/to/efi_binary}}Examples (7)
Show the current secure boot status
sbctl statusCreate custom secure boot keys (by default, everything is stored in `/var/lib/sbctl`)
sbctl create-keysEnroll the custom secure boot keys and Microsoft's UEFI vendor certificates
sbctl enroll-keys [-m|--microsoft]Automatically run `create-keys` and `enroll-keys` based on the settings in `/etc/sbctl/sbctl.conf`
sbctl setup --setupSign an EFI binary with the created key and save the file to the database
sbctl sign [-s|--save] path/to/efi_binaryRe-sign all the saved files
sbctl sign-allVerify that all EFI executables on the EFI system partition have been signed
sbctl verify