A user-friendly secure boot key manager. Note: not enrolling Microsoft’s certificates can brick your system. See https://github.com/Foxboron/sbctl/wiki/FAQ#option-rom. More information: https://github.com/Foxboron/sbctl#usage.
sbctl status
/var/lib/sbctl):sbctl create-keys
sbctl enroll-keys --microsoft
create-keys and enroll-keys based on the settings in /etc/sbctl/sbctl.conf:sbctl setup --setup
sbctl sign -s|--save path/to/efi_binary
sbctl sign-all
sbctl verify