If you want to install your own file sets after activating Trusted Installation, you need the following:
A private key for generating the digital signature of a fileset.
A digital certificate based on the private key.
Optional: the corresponding public key (this can also be extracted from the digital certificate).
The digital certificate must be stored in the Trusted Installation ecosystem (ODM dsc_key and dsc_keystore). The digital signatures of your own fileset must be determined and then stored in the Digital Signature Catalog (DSC). The, your own fileset can be installed.
Note: If there is already a private key with an associated certificate, then these can of course be used and the step of generating keys and certificates can be omitted.