Comment Re: kids these days ... (Score 1) 109
Your distro can work with secure boot enabled because of a shim that grub uses to boot, and which is signed by Microsoft.
No, completely false, your distro can work with secure boot using MS's shim because you the user are too slack to use the feature properly and correctly.
You do not need any involvement from MS to securely boot Linux. In fact you shouldn't. The keys used for secure boot are under user control and user modifiable. Just follow some step by step instructions online to sign your bootloader and load your custom keys into UEFI. You can then proceed to delete Microsoft's keys rendering their shim useless.
The fun part about this, you can even do this in Windows. Yes, that's right, you can secure boot windows with your own key and delete Microsoft's from your motherboard (well partially delete, MS's key remains present for factory reset purposes, but at least it won't boot anything).