Files
efi-shim-bootloader/gen-key.sh
2026-05-26 03:27:31 -07:00

15 lines
343 B
Bash
Executable File

#!/bin/bash
mkdir -p keys
openssl req -newkey rsa:2048 -nodes \
-keyout keys/signing.key \
-new -x509 -days 3650 \
-config openssl.cnf \
-subj "/CN=iPXE Boot Signing Key" \
-out keys/signing.crt
# DER format — this is the cert.der enroll.efi reads
openssl x509 -in keys/signing.crt -outform DER -out keys/signing.der