Debian now has a signed shim.

a corresponding GRUB binary which passes secure boot. See their
[build script](
* [Managing EFI Boot Loaders for Linux by Rod Smith](
* shim is not in Debian yet (2014-01-02)
* shim is [[!debpts shim-signed desc="in Debian"]] (signed by the
Microsoft UEFI CA)
* [Booting a Self-signed Linux
by Greg Kroah-Hartman
