Sealed images: key management for Secure Boot In the previous post , we walked through the security chain that sealed images provide, from firmware through runtime file verification. That chain depends on cryptographic keys at every step. In this post, we’ll cover the keys involved, how to generate them, and how they get enrolled into your system’s firmware.