This spec was implemented in the Kilo cycle.
See ../kilo-implemented/uefi-secure-boot.
../kilo-implemented/uefi-secure-boot