I just noticed that the OpenStack project has an alternative to UEFI Secure Boot, for iLO drivers:
Some of the Ironic deploy drivers support UEFI boot. It would be useful to security sensitive users to deploy more securely using Secure Boot feature of the UEFI. This spec proposes alternatives to support Secure Boot in baremetal provisioning for iLO drivers. […]
https://specs.openstack.org/openstack/ironic-specs/specs/kilo-implemented/uefi-secure-boot.html
https://blueprints.launchpad.net/ironic/+spec/uefi-secure-boot
