Steve McIntyre has posted a long message to the debian-efi mailing list, with a summary of the “Secure Boot BoF” from the last Debian Conference earlier this year(DebConf19), with a good summary of how Debian implements UEFI Secure Boot:
https://lists.debian.org/debian-efi/2019/10/msg00051.html
https://www.einval.com/~steve/talks/Debconf19-SecureBoot/
More info:
https://wiki.debian.org/SecureBoot