Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Next revision Both sides next revision
appnote:etoken [2016/05/10 22:41]
mcb30
appnote:etoken [2018/07/05 21:36]
mcb30
Line 50: Line 50:
 ==== Toolchain ==== ==== Toolchain ====
  
-{{ :​clipart:​chain.jpeg?​300x144|A (tool)chain}}+{{ :​clipart:​chain.jpeg?​300x180|A (tool)chain}}
  
 To sign UEFI .cab files for submission to Microsoft you will need to also install To sign UEFI .cab files for submission to Microsoft you will need to also install
  
   * ''​[[https://​github.com/​rhinstaller/​pesign|pesign]]''​   * ''​[[https://​github.com/​rhinstaller/​pesign|pesign]]''​
-  * ''​[[http://​ohnopub.net/~ohnobinki/lcab/|lcab]]''​+  * ''​[[http://​ftp.gnome.org/​pub/GNOME/sources/gcab|gcab]]''​
   * ''​[[https://​www.openssl.org|openssl]]''​   * ''​[[https://​www.openssl.org|openssl]]''​
   * ''​[[https://​github.com/​OpenSC/​OpenSC/​wiki/​Engine-pkcs11-quickstart|engine_pkcs11]]''​   * ''​[[https://​github.com/​OpenSC/​OpenSC/​wiki/​Engine-pkcs11-quickstart|engine_pkcs11]]''​
Line 82: Line 82:
 To create a UEFI signing submission, you must create a ''​.cab''​ file containing your (unsigned) ''​.efi''​ files. ​ For example, you can create a ''​submission.cab''​ file containing ''​[[http://​boot.ipxe.org/​ipxe.efi|ipxe.efi]]''​ and ''​[[http://​boot.ipxe.org/​snponly.efi|snponly.efi]]''​ using To create a UEFI signing submission, you must create a ''​.cab''​ file containing your (unsigned) ''​.efi''​ files. ​ For example, you can create a ''​submission.cab''​ file containing ''​[[http://​boot.ipxe.org/​ipxe.efi|ipxe.efi]]''​ and ''​[[http://​boot.ipxe.org/​snponly.efi|snponly.efi]]''​ using
  
-    ​lcab -n -ipxe.efi snponly.efi ​submission.cab+    ​gcab -n -c submission.cab ​ipxe.efi snponly.efi
  
 You can sign the ''​submission.cab''​ file using You can sign the ''​submission.cab''​ file using
  
-    osslsigncode -pkcs11engine /​usr/​lib64/​openssl/​engines/​engine_pkcs11.so \+    osslsigncode -pkcs11engine /​usr/​lib64/​openssl/​engines/​pkcs11.so \
                  ​-pkcs11module /​usr/​lib64/​libeToken.so -certs codesigning.crt \                  ​-pkcs11module /​usr/​lib64/​libeToken.so -certs codesigning.crt \
                  -h sha256 -askpass -t http://​timestamp.digicert.com \                  -h sha256 -askpass -t http://​timestamp.digicert.com \
appnote/etoken.txt ยท Last modified: 2023/08/31 10:58 by mcb30
Recent changes RSS feed CC Attribution-Share Alike 4.0 International Driven by DokuWiki
All uses of this content must include an attribution to the iPXE project and the URL https://ipxe.org
References to "iPXE" may not be altered or removed.