summaryrefslogtreecommitdiffstats
path: root/templates/man1/ukify.1.pot
diff options
context:
space:
mode:
Diffstat (limited to 'templates/man1/ukify.1.pot')
-rw-r--r--templates/man1/ukify.1.pot234
1 files changed, 195 insertions, 39 deletions
diff --git a/templates/man1/ukify.1.pot b/templates/man1/ukify.1.pot
index 2174df0f..adbe864b 100644
--- a/templates/man1/ukify.1.pot
+++ b/templates/man1/ukify.1.pot
@@ -7,7 +7,7 @@
msgid ""
msgstr ""
"Project-Id-Version: PACKAGE VERSION\n"
-"POT-Creation-Date: 2024-03-01 17:12+0100\n"
+"POT-Creation-Date: 2024-06-01 06:32+0200\n"
"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n"
"Last-Translator: FULL NAME <EMAIL@ADDRESS>\n"
"Language-Team: LANGUAGE <LL@li.org>\n"
@@ -24,7 +24,7 @@ msgid "UKIFY"
msgstr ""
#. type: TH
-#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: archlinux fedora-40 mageia-cauldron opensuse-tumbleweed
#, no-wrap
msgid "systemd 255"
msgstr ""
@@ -63,6 +63,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "B<ukify> [OPTIONS...] build"
msgstr ""
@@ -74,6 +75,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "B<ukify> [OPTIONS...] inspect FILE..."
msgstr ""
@@ -126,8 +128,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: archlinux debian-bookworm debian-unstable fedora-40 fedora-rawhide
-#: mageia-cauldron opensuse-tumbleweed
+#: archlinux debian-bookworm fedora-40 mageia-cauldron opensuse-tumbleweed
msgid ""
"Additional sections will be inserted into the UKI, either automatically or "
"only if a specific option is provided\\&. See the discussions of I<Cmdline=>/"
@@ -157,8 +158,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: archlinux debian-bookworm debian-unstable fedora-40 fedora-rawhide
-#: mageia-cauldron opensuse-tumbleweed
+#: archlinux debian-bookworm fedora-40 mageia-cauldron opensuse-tumbleweed
msgid ""
"The calculation of PCR values is done for specific boot phase paths\\&. "
"Those can be specified with the I<Phases=>/B<--phases=> option\\&. If not "
@@ -187,6 +187,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"If the stub and/or the kernel contain \"\\&.sbat\" sections they will be "
"merged in the UKI so that revocation updates affecting either are considered "
@@ -222,12 +223,14 @@ msgstr ""
#. type: SS
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
#, no-wrap
msgid "inspect"
msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"Display information about the sections in a given binary or binaries\\&. If "
"B<--all> is given, all sections are shown\\&. Otherwise, if B<--section=> "
@@ -239,6 +242,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "Also see the description of B<-j>/B<--json=> and B<--section=>\\&."
msgstr ""
@@ -265,7 +269,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: archlinux fedora-40 mageia-cauldron opensuse-tumbleweed
msgid ""
"If no config file is provided via the option B<--config=>I<PATH>, B<ukify> "
"will try to look for a default configuration file in the following paths in "
@@ -293,6 +297,7 @@ msgstr ""
#. type: SS
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
#, no-wrap
msgid "Command line-only options"
msgstr ""
@@ -305,6 +310,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"Load configuration from the given config file\\&. In general, settings "
"specified in the config file have lower precedence than the settings "
@@ -315,6 +321,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "Added in version 254\\&."
msgstr ""
@@ -334,11 +341,12 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "Added in version 253\\&."
msgstr ""
#. type: Plain text
-#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: archlinux fedora-40 mageia-cauldron opensuse-tumbleweed
msgid ""
"B<--section=>I<NAME>B<:>I<TEXT>B<|>I<@PATH>, B<--section=>I<NAME>B<:>B<text|"
"binary>B<[@>I<PATH>]"
@@ -346,6 +354,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"For all verbs except B<inspect>, the first syntax is used\\&. Specify an "
"arbitrary additional section \"I<NAME>\"\\&. The argument may be a literal "
@@ -356,6 +365,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"For the B<inspect> verb, the second syntax is used\\&. The section I<NAME> "
"will be inspected (if found)\\&. If the second argument is \"text\", the "
@@ -365,6 +375,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"Note that the name is used as-is, and if the section name should start with "
"a dot, it must be included in I<NAME>\\&."
@@ -408,6 +419,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"Print a summary of loaded config and exit\\&. This is useful to check how "
"the options from the configuration file and the command line are combined\\&."
@@ -415,26 +427,31 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "B<--all>"
msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "Print all sections (with B<inspect> verb)\\&."
msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "Added in version 255\\&."
msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "B<--json>"
msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "Generate JSON output (with B<inspect> verb)\\&."
msgstr ""
@@ -743,16 +760,17 @@ msgid "I<SBAT=>I<TEXT>I<|>I<@PATH>, B<--sbat=>I<TEXT>B<|>I<@PATH>"
msgstr ""
#. type: Plain text
-#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: archlinux debian-unstable fedora-rawhide mageia-cauldron opensuse-tumbleweed
msgid ""
"SBAT metadata associated with the UKI or addon\\&. SBAT policies are useful "
"to revoke whole groups of UKIs or addons with a single, static policy update "
"that does not take space in DBX/MOKX\\&. If not specified manually, a "
-"default metadata entry consisting of \"uki,1,UKI,uki,1,https://www\\&."
-"freedesktop\\&.org/software/systemd/man/systemd-stub\\&.html\" will be used, "
-"to ensure it is always possible to revoke UKIs and addons\\&. For more "
-"information on SBAT see \\m[blue]B<Shim "
-"documentation>\\m[]\\&\\s-2\\u[2]\\d\\s+2\\&."
+"default metadata entry consisting of \"uki,1,UKI,uki,1,https://uapi-group\\&."
+"org/specifications/specs/unified_kernel_image/\" for UKIs and \"uki-addon,1,"
+"UKI Addon,addon,1,https://www\\&.freedesktop\\&.org/software/systemd/man/"
+"latest/systemd-stub\\&.html\" for addons will be used, to ensure it is "
+"always possible to revoke them\\&. For more information on SBAT see "
+"\\m[blue]B<Shim documentation>\\m[]\\&\\s-2\\u[2]\\d\\s+2\\&."
msgstr ""
#. type: SS
@@ -764,6 +782,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"In the config file, those options are grouped by section\\&. On the command "
"line, they must be specified in the same order\\&. The sections specified in "
@@ -778,6 +797,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"A private key to use for signing PCR policies\\&. On the command line, this "
"option may be specified more than once, in which case multiple signatures "
@@ -798,6 +818,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"On the command line, this option may be specified more than once, similarly "
"to the B<--pcr-private-key=> option\\&. If not present, the public keys will "
@@ -824,6 +845,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"On the command line, when this argument is present, it must appear the same "
"number of times as the B<--pcr-private-key=> option\\&."
@@ -866,7 +888,7 @@ msgid "B<Example\\ \\&2.\\ \\&All the bells and whistles>"
msgstr ""
#. type: Plain text
-#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: archlinux debian-unstable fedora-rawhide mageia-cauldron opensuse-tumbleweed
#, no-wrap
msgid ""
"$ ukify build \\e\n"
@@ -874,7 +896,7 @@ msgid ""
" --initrd=early_cpio \\e\n"
" --initrd=/some/path/initramfs-6\\&.0\\&.9-300\\&.fc37\\&.x86_64\\&.img \\e\n"
" --sbat=\\*(Aqsbat,1,SBAT Version,sbat,1,https://github\\&.com/rhboot/shim/blob/main/SBAT\\&.md\n"
-" uki\\&.author\\&.myimage,1,UKI for System,uki\\&.author\\&.myimage,1,https://www\\&.freedesktop\\&.org/software/systemd/man/systemd-stub\\&.html\\*(Aq \\e\n"
+" uki\\&.author\\&.myimage,1,UKI for System,uki\\&.author\\&.myimage,1,https://uapi-group\\&.org/specifications/specs/unified_kernel_image/\\*(Aq \\e\n"
" --pcr-private-key=pcr-private-initrd-key\\&.pem \\e\n"
" --pcr-public-key=pcr-public-initrd-key\\&.pem \\e\n"
" --phases=\\*(Aqenter-initrd\\*(Aq \\e\n"
@@ -965,6 +987,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
#, no-wrap
msgid ""
"$ ukify -c ukify\\&.conf build \\e\n"
@@ -974,6 +997,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"One \"initrd\" (early_cpio) is specified in the config file, and the other "
"initrd (initramfs-6\\&.0\\&.9-300\\&.fc37\\&.x86_64\\&.img) is specified on "
@@ -989,8 +1013,7 @@ msgid "B<Example\\ \\&4.\\ \\&Kernel command line auxiliary PE>"
msgstr ""
#. type: Plain text
-#: archlinux debian-bookworm debian-unstable fedora-40 fedora-rawhide
-#: mageia-cauldron opensuse-tumbleweed
+#: archlinux debian-unstable fedora-rawhide mageia-cauldron opensuse-tumbleweed
#, no-wrap
msgid ""
"ukify build \\e\n"
@@ -998,7 +1021,7 @@ msgid ""
" --secureboot-certificate=sb\\&.cert \\e\n"
" --cmdline=\\*(Aqdebug\\*(Aq \\e\n"
" --sbat=\\*(Aqsbat,1,SBAT Version,sbat,1,https://github\\&.com/rhboot/shim/blob/main/SBAT\\&.md\n"
-" uki\\&.addon\\&.author,1,UKI Addon for System,uki\\&.addon\\&.author,1,https://www\\&.freedesktop\\&.org/software/systemd/man/systemd-stub\\&.html\\*(Aq\n"
+" uki-addon\\&.author,1,UKI Addon for System,uki-addon\\&.author,1,https://www\\&.freedesktop\\&.org/software/systemd/man/systemd-stub\\&.html\\*(Aq\n"
" --output=debug\\&.cmdline\n"
msgstr ""
@@ -1069,6 +1092,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
#, no-wrap
msgid ""
"# ukify genkey --config=/etc/kernel/uki\\&.conf\n"
@@ -1090,6 +1114,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid ""
"Subsequent invocations using the config file (B<ukify build --config=/etc/"
"kernel/uki\\&.conf>) will use this certificate and key files\\&. Note that "
@@ -1149,6 +1174,7 @@ msgstr ""
#. type: Plain text
#: archlinux debian-unstable fedora-40 fedora-rawhide mageia-cauldron
+#: opensuse-tumbleweed
msgid "Shim documentation"
msgstr ""
@@ -1159,18 +1185,18 @@ msgid "\\%https://github.com/rhboot/shim/blob/main/SBAT.md"
msgstr ""
#. type: TH
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
#, no-wrap
msgid "systemd 254"
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid "B</usr/lib/systemd/ukify> [OPTIONS...] build"
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"Note: this command is experimental for now\\&. While it is intended to "
"become a regular component of systemd, it might still change in behaviour "
@@ -1178,7 +1204,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"If the stub and/or the kernel contain \"\\&.sbat\" sections they will be "
"merged in the UKI so that revocation updates affecting either are considered "
@@ -1187,13 +1213,13 @@ msgid ""
msgstr ""
#. type: SS
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
#, no-wrap
msgid "Commandline-only options"
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"Load configuration from the given config file\\&. In general, settings "
"specified in the config file have lower precedence than the settings "
@@ -1203,12 +1229,12 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid "B<--section=>I<NAME>B<:>I<TEXT>B<|>I<@PATH>"
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"Specify an arbitrary additional section \"I<NAME>\"\\&. Note that the name "
"is used as-is, and if the section name should start with a dot, it must be "
@@ -1219,14 +1245,14 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"Print a summary of loaded config and exit\\&. This is useful to check how "
"the options form the configuration file and the commandline are combined\\&."
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"SBAT metadata associated with the UKI or addon\\&. SBAT policies are useful "
"to revoke whole groups of UKIs or addons with a single, static policy update "
@@ -1239,7 +1265,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"In the config file, those options are grouped by section\\&. On the "
"commandline, they must be specified in the same order\\&. The sections "
@@ -1247,7 +1273,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"A private key to use for signing PCR policies\\&. On the commandline, this "
"option may be specified more than once, in which case multiple signatures "
@@ -1255,7 +1281,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"On the commandline, this option may be specified more than once, similarly "
"to the B<--pcr-private-key=> option\\&. If not present, the public keys will "
@@ -1265,14 +1291,14 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"On the commandline, when this argument is present, it must appear the same "
"number of times as the B<--pcr-private-key=> option\\&."
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
#, no-wrap
msgid ""
"$ /usr/lib/systemd/ukify build \\e\n"
@@ -1296,7 +1322,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
#, no-wrap
msgid ""
"$ /usr/lib/systemd/ukify -c ukify\\&.conf build \\e\n"
@@ -1305,7 +1331,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"One \"initrd\" (early_cpio) is specified in the config file, and the other "
"initrd (initramfs-6\\&.0\\&.9-300\\&.fc37\\&.x86_64\\&.img) is specified on "
@@ -1315,7 +1341,20 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm fedora-40
+#, no-wrap
+msgid ""
+"ukify build \\e\n"
+" --secureboot-private-key=sb\\&.key \\e\n"
+" --secureboot-certificate=sb\\&.cert \\e\n"
+" --cmdline=\\*(Aqdebug\\*(Aq \\e\n"
+" --sbat=\\*(Aqsbat,1,SBAT Version,sbat,1,https://github\\&.com/rhboot/shim/blob/main/SBAT\\&.md\n"
+" uki\\&.addon\\&.author,1,UKI Addon for System,uki\\&.addon\\&.author,1,https://www\\&.freedesktop\\&.org/software/systemd/man/systemd-stub\\&.html\\*(Aq\n"
+" --output=debug\\&.cmdline\n"
+msgstr ""
+
+#. type: Plain text
+#: debian-bookworm
#, no-wrap
msgid ""
"# /usr/lib/systemd/ukify genkey --config=/etc/kernel/uki\\&.conf\n"
@@ -1328,7 +1367,7 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid ""
"Subsequent invocations of using the config file (B</usr/lib/systemd/ukify "
"build --config=/etc/kernel/uki\\&.conf>) will use this certificate and key "
@@ -1339,6 +1378,123 @@ msgid ""
msgstr ""
#. type: Plain text
-#: debian-bookworm opensuse-tumbleweed
+#: debian-bookworm
msgid "Shim's documentation."
msgstr ""
+
+#. type: TH
+#: debian-unstable fedora-rawhide
+#, no-wrap
+msgid "systemd 256~rc3"
+msgstr ""
+
+#. type: Plain text
+#: debian-unstable fedora-rawhide
+msgid ""
+"Additional sections will be inserted into the UKI, either automatically or "
+"only if a specific option is provided\\&. See the discussions of "
+"I<Microcode=>/B<--microcode=>, I<Cmdline=>/B<--cmdline=>, I<OSRelease=>/B<--"
+"os-release=>, I<DeviceTree=>/B<--devicetree=>, I<Splash=>/B<--splash=>, "
+"I<PCRPKey=>/B<--pcrpkey=>, I<Uname=>/B<--uname=>, I<SBAT=>/B<--sbat=>, and "
+"B<--section=> below\\&."
+msgstr ""
+
+#. type: Plain text
+#: debian-unstable fedora-rawhide
+msgid ""
+"The calculation of PCR values is done for specific boot phase paths\\&. "
+"Those can be specified with the I<Phases=>/B<--phases=> option\\&. If not "
+"specified, the default provided by B<systemd-measure> is used\\&. It is also "
+"possible to specify the I<PCRPrivateKey=>/B<--pcr-private-key=>, "
+"I<PCRPublicKey=>/B<--pcr-public-key=>, and I<Phases=>/B<--phases=> arguments "
+"more than once\\&. Signatures will then be performed with each of the "
+"specified keys\\&. On the command line, when both B<--phases=> and B<--pcr-"
+"private-key=> are used, they must be specified the same number of times, and "
+"then the n-th boot phase path set will be signed by the n-th key\\&. This "
+"can be used to build different trust policies for different phases of the "
+"boot\\&. In the config file, I<PCRPrivateKey=>, I<PCRPublicKey=>, and "
+"I<Phases=> are grouped into separate sections, describing separate boot "
+"phases\\&. If I<SigningEngine=>/B<--signing-engine=> is specified, then the "
+"private keys arguments will be passed verbatim to OpenSSL as URIs, and the "
+"public key arguments will be loaded as X\\&.509 certificates, so that "
+"signing can be performed with an OpenSSL engine\\&."
+msgstr ""
+
+#. type: Plain text
+#: debian-unstable fedora-rawhide
+msgid ""
+"Other tools that may be useful for inspect UKIs: B<llvm-objdump>(1) B<-p> "
+"and B<pe-inspect>\\&."
+msgstr ""
+
+#. type: Plain text
+#: debian-unstable fedora-rawhide
+msgid ""
+"If no config file is provided via the option B<--config=>I<PATH>, B<ukify> "
+"will try to look for a default configuration file in the following paths in "
+"this order: /etc/systemd/ukify\\&.conf, /run/systemd/ukify\\&.conf, /usr/"
+"local/lib/systemd/ukify\\&.conf, and /usr/lib/systemd/ukify\\&.conf, and "
+"then load the first one found\\&. B<ukify> will proceed normally if no "
+"configuration file is specified and no default one is found\\&."
+msgstr ""
+
+#. type: Plain text
+#: debian-unstable fedora-rawhide
+msgid ""
+"B<--section=>I<NAME>B<:>I<TEXT>B<|>I<@PATH>, B<--section=>I<NAME>B<:text|"
+"binary>B<[@>I<PATH>]"
+msgstr ""
+
+#. type: Plain text
+#: debian-unstable fedora-rawhide
+msgid "I<Microcode=>I<UCODE>, B<--microcode=>I<UCODE>"
+msgstr ""
+
+#. type: Plain text
+#: debian-unstable fedora-rawhide
+msgid ""
+"Path to initrd containing microcode updates\\&. If not specified, the "
+"section will not be present\\&."
+msgstr ""
+
+#. type: Plain text
+#: debian-unstable fedora-rawhide
+msgid "Added in version 256\\&."
+msgstr ""
+
+#. type: Plain text
+#: fedora-40
+msgid ""
+"SBAT metadata associated with the UKI or addon\\&. SBAT policies are useful "
+"to revoke whole groups of UKIs or addons with a single, static policy update "
+"that does not take space in DBX/MOKX\\&. If not specified manually, a "
+"default metadata entry consisting of \"uki,1,UKI,uki,1,https://www\\&."
+"freedesktop\\&.org/software/systemd/man/systemd-stub\\&.html\" will be used, "
+"to ensure it is always possible to revoke UKIs and addons\\&. For more "
+"information on SBAT see \\m[blue]B<Shim "
+"documentation>\\m[]\\&\\s-2\\u[2]\\d\\s+2\\&."
+msgstr ""
+
+#. type: Plain text
+#: fedora-40
+#, no-wrap
+msgid ""
+"$ ukify build \\e\n"
+" --linux=/lib/modules/6\\&.0\\&.9-300\\&.fc37\\&.x86_64/vmlinuz \\e\n"
+" --initrd=early_cpio \\e\n"
+" --initrd=/some/path/initramfs-6\\&.0\\&.9-300\\&.fc37\\&.x86_64\\&.img \\e\n"
+" --sbat=\\*(Aqsbat,1,SBAT Version,sbat,1,https://github\\&.com/rhboot/shim/blob/main/SBAT\\&.md\n"
+" uki\\&.author\\&.myimage,1,UKI for System,uki\\&.author\\&.myimage,1,https://www\\&.freedesktop\\&.org/software/systemd/man/systemd-stub\\&.html\\*(Aq \\e\n"
+" --pcr-private-key=pcr-private-initrd-key\\&.pem \\e\n"
+" --pcr-public-key=pcr-public-initrd-key\\&.pem \\e\n"
+" --phases=\\*(Aqenter-initrd\\*(Aq \\e\n"
+" --pcr-private-key=pcr-private-system-key\\&.pem \\e\n"
+" --pcr-public-key=pcr-public-system-key\\&.pem \\e\n"
+" --phases=\\*(Aqenter-initrd:leave-initrd enter-initrd:leave-initrd:sysinit \\e\n"
+" enter-initrd:leave-initrd:sysinit:ready\\*(Aq \\e\n"
+" --pcr-banks=sha384,sha512 \\e\n"
+" --secureboot-private-key=sb\\&.key \\e\n"
+" --secureboot-certificate=sb\\&.cert \\e\n"
+" --sign-kernel \\e\n"
+" --cmdline=\\*(Aqquiet rw rhgb\\*(Aq\n"
+msgstr ""