Matthew Garrett has published a UEFI Secure Boot best practices document. It was sent as an attachment to the fw-summit@lists.linaro.org.
Excellent read, if you care about Secure Boot, read this document.
Full article:
https://lists.linaro.org/pipermail/fw-summit/2015-September/000170.html
Read Matthew’s document!
