Use shim-signed and shim-helpers-{arch}-signed from Debian: https://packages.debian.org/bookworm/shim-signed