Description of problem: I wrote this a couple of weeks ago: http://jwboyer.livejournal.com/46149.html It details building a custom kernel. Feel free to use anything you'd like from there. However, it doesn't cover: - generating your own key/certs - signing shim or grub2 (trivially derived from the existing kernel example) - third party module signing Peter is working on a tool to make generating certs that UEFI likes easier for people. I was waiting for that tool to be available before really covering those aspects, as that is what we want users to use.
I'm going to defer on getting the information from Peter before updating this chapter. I've removed the chapter from the final product for now.
On a related topic: There's no Documentation/module-signing.txt file. Under "config MODULE_SIG", init/Kconfig, states: For more information see Documentation/module-signing.txt.