Above produced with: $ sbattach --detach signature /mnt/EFI/BOOT/BOOTx64.EFI $ openssl pkcs7 -inform DER -in signature -text -print_certs
Above produced with: BOOT/BOOTx64. EFI
$ sbattach --detach signature /mnt/EFI/
$ openssl pkcs7 -inform DER -in signature -text -print_certs