Sign in-toto link or layout metadata or verify their signatures. More information: https://in-toto.readthedocs.io/en/latest/command-line-tools/in-toto-sign.html.
in-toto-sign -f unsigned.layout -k priv_key1 priv_key2 -o root.layout
in-toto-sign -f package.2f89b927.link -k priv_key
in-toto-sign -f root.layout -k pub_key0 pub_key1 pub_key2 --verify
in-toto-sign -f root.layout --gpg
in-toto-sign -f root.layout --verify --gpg ...439F3C2