gramine-sgx-sign – Gramine
gramine-sgx-sign [OPTION]… –output output_manifest –key key_file –manifest manifest_file
gramine-sgx-sign is used to expand Trusted Files and generate signature file for given input manifest and libpal file (main Gramine binary).
Command line arguments¶
Show help and exit.
Path to the output manifest file (with Trusted Files expanded).
Path to the private key used for signing.
Input manifest file.
Set specific date to be put into
SIGSTRUCT. If not given, or the value is literal
today, then current day according to system calendar is used. Otherwise expects
<YYYY>-<MM>-<DD>. The date needs not to be a valid day, it will happily accept
--date 0000-00-00, e.g. for reproducible builds.
Path to libpal file (main Gramine binary).
Path to the output file containing
SIGSTRUCT. If not provided, manifest_file will be used with “.manifest” (if present) removed from the end and with “.sig” appended.
Generate a file that describes the dependencies for the output manifest and
SIGSTRUCT, i.e. files that should trigger rebuilding if they’re modified. The dependency file is in Makefile format, and is suitable for using in build systems (Make, Ninja).
Print details to standard output. This is the default.
Don’t print details to standard output.
Use plugin to perform actual signing. The default plugin is
file, which signs the
SIGSTRUCTusing PEM-encoded local file. The list of available plugins is at the end of
Each plugin may add its own set of options (usually in the form of
--<plugin>-<option>). To get help about those, use gramine-sgx-sign --with=<plugin> --help-<plugin> and/or consult the documentation of the respective plugin.