Linux app/lib/script that checks CSF signature

To do a firmware upgrade, I would like to verify the CSF signature in user space prior to installing the new firmware.  It seems a user space app can read the SRK fuses and duplicate the signing algorithm using OpenSSL.  Is there an app/lib/script already available that does this? If not, what is the algorithm the CST tool uses for creating the CSF signature?    One could also use this to test the cst tool itself without using the iMX platform.