you may see-also below for details. $public_sources/r35.5.0/Linux_for_Tegra/source/public/atf_and_optee/optee/samples/ftpm-helper/README.md $public_sources/r35.5.0/Linux_for_Tegra/source/public/atf_and_optee/optee/samples/ftpm-helper/host/tool/oem_ekb_gen.py
it’s explained here… $public_sources/r35.5.0/Linux_for_Tegra/source/public/atf_and_optee/optee/samples/hwkey-agent/host/tool/gen_ekb/README -in_device_id: A device ID cert in DER format [t234 only]