generation process described in boot/bootutil/ signed_images.md (or maybe doc/signed_images.md) § Somewhat involved process, but only has to be done once § use OpenSSL to create private, extract public, dump as C, add new file with required key vars, rebuild!