我发出以下命令来为文件创建签名(linux内核):
openssl ca -config ca.cnf -extensions codesigning -in codesign.req -out codesign.crt
openssl cms -sign -binary -noattr -in vmlinuz -signer codesign.crt -inkey codesign.key -certfile ca.crt -outform DER -out vmlinuz.sig
ca.cnf文件适用于我自己的私有CA基础架构,它具有digitalSignature密钥用法扩展和codeSigning扩展密钥用法扩展。
我怎样才能验证vmlinuz.sig是vmlinuz的签名?