This script uses openssl to mock a TPM 2.0 manufacturer's [Endorsement Key credentials][r4] enough to use in acceptance tests starting with fresh EKs from a newly-instantiated [TPM 2.0 simulator][tpm2sim].
bash -e tpm2_ekcert_sign.sh [public.ek.portion.cer]