Description
Unified kernel images and Secure Boot signing can be managed from a shell workflow for UEFI systems. ukpdate is for administrators maintaining bootable UKI files and related signing tools.
Run it only with a recovery path and known-good boot entries available. Boot image or signing mistakes can leave a machine unbootable, invalidate Secure Boot trust, or overwrite critical EFI files.