EnglishFrenchSpanish

OnWorks favicon

pesign - Online in the Cloud

Run pesign in OnWorks free hosting provider over Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator

This is the command pesign that can be run in the OnWorks free hosting provider using one of our multiple free online workstations such as Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator

PROGRAM:

NAME


pesign - command line tool for signing UEFI applications

SYNOPSIS


pesign [--in=infile | -i infile]
[--out=outfile | -o outfile]
[--certdir=certdir/fR | -n certdir]
[--nss-token=token | -t token]
[--certificate=nickname | -c nickname]
[--force | -f] [--sign | -s] [--hash | -h]
[--digest_type=digest | -d digest]
[--show-signature | -S ] [--remove-signature | -r ]
[--export-pubkey=outkey | -K outkey]
[--export-cert=outcert | -C outcert]
[--ascii-armor | -a] [--daemonize | -D] [--nofork | -N]
[--signature-number=signum | -u signum]

DESCRIPTION


pesign is a command line tool for manipulating signatures and cryptographic digests of
UEFI applications.

OPTIONS


--in=infile
Specify input binary.

--out=outfile
Specify output binary.

--certdir=certdir
Specify nss certificate database directory.

--nss-token=token
Use the specified NSS token's certificate database.

--certificate=nickname
Use the certificate database entry with the specified nickname for signing.

--force
Overwrite output files. Without this parameter, pesign will refuse to overrite any
output files which already exist.

--sign Sign the input binary with the key specified by --certificate.

--hash Display the cryptographic digest of the input binary on standard output.

--digest_type=digest
Use the specified digest in hashing and signing operations. By default, this value
is "sha256". Use "--digest_type=help" to list the available digests.

--show-signature
Show information about the signature of the input binary.

--remove-signature
Remove the signature section from the binary.

--signature-number=signum
Specify which signature to operate on. This field is zero-indexed.

--export-pubkey=outkey
Export the public key specified by --certificate to outkey

--export-cert=outcert
Export the certificate specified by --certificate to outcert

--ascii
Use ascii armoring on exported certificates.

--daemonize
Spawn a daemon for use with pesign-client(1)

--nofork
Do not fork when using --daemonize.

EXAMPLES


If you have a certificate file and private key file, the following steps may be used to
sign a PE image:

# Create a pkcs12 file from private key and
# certificate file.
host:~$ openssl pkcs12 -export -out foo_key.p12 \
-inkey signing_key.pem \
-in xyz_cert.x509.pem

# Import pkcs12 file into pesign db
host:~$ pk12util -i foo_key.p12 -d /etc/pki/pesign

# Do the signing
host:~$ pesign -i <input-file> -o <output-file> \
-c <cert nickname> -s

Please note that this is just an example, and that recommended best practice is to always
store private keys in a FIPS 140-2 hardware security module, level 2 or higher.

Use pesign online using onworks.net services


Free Servers & Workstations

Download Windows & Linux apps

  • 1
    Phaser
    Phaser
    Phaser is a fast, free, and fun open
    source HTML5 game framework that offers
    WebGL and Canvas rendering across
    desktop and mobile web browsers. Games
    can be co...
    Download Phaser
  • 2
    VASSAL Engine
    VASSAL Engine
    VASSAL is a game engine for creating
    electronic versions of traditional board
    and card games. It provides support for
    game piece rendering and interaction,
    and...
    Download VASSAL Engine
  • 3
    OpenPDF - Fork of iText
    OpenPDF - Fork of iText
    OpenPDF is a Java library for creating
    and editing PDF files with a LGPL and
    MPL open source license. OpenPDF is the
    LGPL/MPL open source successor of iText,
    a...
    Download OpenPDF - Fork of iText
  • 4
    SAGA GIS
    SAGA GIS
    SAGA - System for Automated
    Geoscientific Analyses - is a Geographic
    Information System (GIS) software with
    immense capabilities for geodata
    processing and ana...
    Download SAGA GIS
  • 5
    Toolbox for Java/JTOpen
    Toolbox for Java/JTOpen
    The IBM Toolbox for Java / JTOpen is a
    library of Java classes supporting the
    client/server and internet programming
    models to a system running OS/400,
    i5/OS, o...
    Download Toolbox for Java/JTOpen
  • 6
    D3.js
    D3.js
    D3.js (or D3 for Data-Driven Documents)
    is a JavaScript library that allows you
    to produce dynamic, interactive data
    visualizations in web browsers. With D3
    you...
    Download D3.js
  • More »

Linux commands

Ad