openssl cms -sign -binary -noattr -in kernel.efi \ -signer codesign.crt -inkey codesign.key -certfile ca.crt \ -outform DER -out kernel.efi.sig