pesign - Signing utility for UEFI binaries

Property Value
Distribution Ubuntu 19.04 (Disco Dingo)
Repository Ubuntu Universe amd64
Package filename pesign_0.112-4_amd64.deb
Package name pesign
Package version 0.112
Package release 4
Package architecture amd64
Package type deb
Category universe/devel
License -
Maintainer Ubuntu Developers <>
Download size 88.75 KB
Installed size 532.00 KB
This package contains the pesign utility for signing UEFI binaries (PE-COFF
format) as well as other associated tools. It is meant to follow the PE and
Authenticode specifications. It is analogous to the tool described at


Package Version Architecture Repository
pesign_0.112-4_i386.deb 0.112 i386 Ubuntu Universe
pesign - - -


Name Value
coolkey -
libc6 >= 2.14
libefivar1 >= 30
libnspr4 >= 2:4.10.9
libnss3 >= 2:3.15
libnss3-tools -
libpopt0 >= 1.14
libuuid1 >= 2.16
opensc -


Type URL
Binary Package pesign_0.112-4_amd64.deb
Source Package pesign

Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install pesign deb package:
    # sudo apt-get install pesign




2017-05-13 - Julien Cristau <>
pesign (0.112-4) unstable; urgency=medium
* Team upload.
* Fix race between printing prompt and disabling tty echo.
2016-06-27 - Julien Cristau <>
pesign (0.112-3) unstable; urgency=medium
* Team upload.
* Pass libexecdir correctly to sub-makes so the service file has the right
2016-06-27 - Steve McIntyre <>
pesign (0.112-2) unstable; urgency=medium
[ Julien Cristau ]
* Fix pesign service file installation. Closes: #828192
* Fix command line parsing. Closes: #828682
2016-04-20 - Daniel Jared Dominguez <>
pesign (0.112-1) unstable; urgency=low
[ Daniel Jared Dominguez ]
* update VCS info
* use debian-efi list as maintainer
[ Peter Jones ]
* Make "make install_systemd" and "make install_sysvinit" not error.
* Install authvar and efisiglist
* Make --clear without --export actually work.
* Make x509 certs in siglists work.
* Ignore some things that wind up in a working tree pretty often.
* make efi_guid_t's const.
[ Pat Riehecky ]
* A more plugable way of setting ACLs for pesign
[ Peter Jones ]
* Propogate some "const" declarations better.
* Make efivar compiler parameters come from pkg-config.
* Add "install" targets for 3c2374b and make the filenames a little nicer.
[ Daniel Jared Dominguez ]
* add manpages for authvar/efisiglist and escape dashes in existing manpages
[ Peter Jones ]
* Make pesign-authorize-{users,groups} not be in sbin.
[ Gary Ching-Pang Lin ]
* Correct the signature size check
[ Peter Jones ]
* Revamp the makefile system entirely.
* Don't let make autogenerate a rule for "%".
* Fix some -Wsign-compare warnings
* Bump version to 0.111
* Fix one more -Wsign-compare problem I missed.
* pesign: when nss fails to tell us -EPERM or -ENOENT, figure it out.
* setfacl the nss DBs to our authorized users, not just the socket.
* Don't setfacl when the socket or dir aren't there.
* setfacl the db as well
* Get rid of KeyIdTemplate; it is unused.
[ Mirco Tischler ]
* fix double $prefix when installing to $docdir
[ Peter Jones ]
* libdpe: Fix a plausible but unrealistic "may be used uninitialized"
* Fix our makefile rule so the target binaries are getting linked -g
* efikeygen: fix missing libefivar dep for efi_guid_zero
* pesigcheck pesign: use LDLIBS+= to link in libdpe.a
* efikeygen: don't hide --dbdir option
* authvar: add --list-supported-sigs
* Minor whitespace fix.
* Make -Werror=unused-parameter work.
* Make -Werror=type-limits work.
* Make -Werror=missing-field-initializers work.
* make pesigcheck be able to get cert dbs from a file
* makefile crap
* try even harder to restrict the time checking in pesigcheck
* pesigcheck: check dbfile and dbxfile from popt
* efisiglist: add --infile
* libdpe: get rid of all the stupid locking
* Make things that don't touch PE not need libdpe.
* Improve our setfacl scripts for database and socket ownership.
* Do a better job of isolating pesign-rh-test-crap
* Bump version to 0.112
[ Daniel Jared Dominguez ]
* new upstream release (Closes: #819766)
* remove old quilt patches
2015-07-29 - Daniel Jared Dominguez <>
pesign (0.110-3) UNRELEASED; urgency=low
* update VCS info
* use debian-efi list as maintainer
2015-06-23 - Daniel Jared Dominguez <>
pesign (0.110-2) unstable; urgency=medium
* uncomment VCS information in debian/control
* change package priority because of dependency on opensc
2015-05-21 - Daniel Jared Dominguez <>
pesign (0.110-1) unstable; urgency=low
* Initial release (Closes: #786462)

See Also

Package Description
petit_1.1.1-1_all.deb log analysis tool for syslog, apache and raw log files
petitboot-twin_13. Twin GUI version of petitboot, a kexec based bootloader
petitboot_13. ncurses version of petitboot, a kexec based bootloader
petname_2.7-0ubuntu1_all.deb generate pronouncable, perhaps even memorable, pet names
petri-foo_0.1.87-4build1_amd64.deb MIDI controllable audio sampler - successor of specimen
petris_1.0.1-10build1_amd64.deb Peter's Tetris - a Tetris(TM) clone
petsc-dev_3.10.5+dfsg1-1_all.deb Virtual package depending on latest PETSc development package
petsc3.10-doc_3.10.5+dfsg1-1_all.deb Documentation and examples for PETSc
pev_0.80-4build1_amd64.deb text-based tool to analyze PE files
pex_1.1.14-2ubuntu2_all.deb library for generating Python executable zip files
pexec_1.0~rc8-4_amd64.deb Executing commands in parallel
pfb2t1c2pfb_0.3-11_amd64.deb convert pfb into more compressible format and back
pff-tools_20180714-1_amd64.deb utilities for MS Outlook PAB, PST and OST files
pflogsumm_1.1.5-5_all.deb Postfix log entry summarizer
pfm_2.0.8-3_all.deb PostgreSQL graphical client using Tcl/Tk