gpg can't be used for the signing, because it doesn't know how to do authenticode. If you can use it to generate an x509 cert and key then you can certainly use that as your signing key.
Power management, mobile and firmware developer on Linux. Security developer at nvidia. Ex-biologist. Content here should not be interpreted as the opinion of my employer. Also on Mastodon and Bluesky.
no subject
Date: 2012-12-09 07:19 pm (UTC)