openssl cms -sign -binary -noattr -in kernel.efi \
-signer codesign.crt -inkey codesign.key -certfile ca.crt \
-outform DER -out kernel.efi.sig