OnWorks favicon

efi-updatevar - Online in the Cloud

Run efi-updatevar in OnWorks free hosting provider over Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator

This is the command efi-updatevar that can be run in the OnWorks free hosting provider using one of our multiple free online workstations such as Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator



efi-updatevar - tool for updating secure variables


efi-updatevar: [-a] [-e] [-d <list>[-<entry>]] [-k <key>] [-g <guid>] [-b <file>|-f
<file>|-c file] <var>


Takes a variety of input files and adds them to one of the UEFI secure boot signature or
key databases.

Note that the efivarfs filesystem must be mounted somewhere on the box and efi-updatevars
must have the ability to write to the files (this usually means it must run as root).

Manipulate the UEFI key database via the efivarfs filesystem


-a append a value to the variable instead of replacing it

-e use EFI Signature List instead of signed update (only works in Setup Mode

-b <binfile>
Add hash of <binfile> to the signature list

-f <file>
Add or Replace the key file (.esl or .auth) to the <var>

-c <file>
Add or Replace the x509 certificate to the <var> (with <guid> if provided)

-g <guid>
Optional <guid> for the X509 Certificate

-k <key>
Secret key file for authorising User Mode updates

-d <list>[-<entry>]
Delete the signature list <list> (or just a single <entry> within the list)


Assuming you own your own platform key and have the PK.auth and noPK.auth files which go
with it, you can programmatically move the system out of User Mode by doing

efi-updatevar -f noPK.auth PK

and put it back again with

efi-updatevar -f PK.auth PK

To add the hash of an efi binary bin.efi to db in Setup Mode do

efi-updatevar -b bin.efi db

And to append an EFI signature list append.esl to db in Setup Mode do

efi-updatevar -a -e append.esl db

To add your key (KEK.crt) to the Key Exchange Key in User Mode, assuming the private part
of the platform key is in PK.key, do

efi-updatevar -a -c KEK.crt -k PK.key KEK

To add certificate DB.crt to db in User Mode assuming the private part of the Key Exchange
Key (KEK) is in KEK.key do

efi-updatevar -a -c DB.crt -k KEK.key db

To replace the old platform key (PK) with a new one in newPK.crt in User Mode assuming the
private part of the old platform key is in PK.key, do

efi-updatevar -c newPK.crt -k PK.key db

To delete the private key, tipping the platform from User Mode to Setup Mode, do

efi-updatevar -d 0 -k PK.key PK

And to put the private key back again (in Setup Mode) do

efi-updatevar -c PK.crt -k PK.key PK

Use efi-updatevar online using onworks.net services

Free Servers & Workstations

Download Windows & Linux apps

  • 1
    MSYS2 is a collection of tools and
    libraries providing you with an
    easy-to-use environment for building,
    installing and running native Windows
    software. It con...
    Download MSYS2
  • 2
    DOSBox emulates a full x86 pc with
    sound and DOS. Its main use is to run
    old DOS games on platforms which
    don't have DOS (Windows 7, 8, 8.1
    and 10 / Linux ...
    Download DOSBox
  • 3
    Xtreme Download Manager
    Xtreme Download Manager
    The project has a new home now:
    https://xtremedownloadmanager.com/ For
    https://github.com/subhra74/xdm Xtreme
    Download Manager is a powerful tool t...
    Download Xtreme Download Manager
  • 4
    Clover EFI bootloader
    Clover EFI bootloader
    Project has moved to
    Features:Boot macOS, Windows, and Linux
    in UEFI or legacy mode on Mac or PC with
    Download Clover EFI bootloader
  • 5
    Sequelize is a promise-based Node.js
    ORM for Postgres, MySQL, MariaDB, SQLite
    and Microsoft SQL Server. It features
    solid transaction support, relations,
    Download Sequelize
  • 6
    Join us in Gitter!
    Enable the URPMS repository in your
    system -
    Download unitedrpms
  • 7
    Boost C++ Libraries
    Boost C++ Libraries
    Boost provides free portable
    peer-reviewed C++ libraries. The
    emphasis is on portable libraries which
    work well with the C++ Standard Library.
    See http://www.bo...
    Download Boost C++ Libraries
  • More »

Linux commands