I've not done it personally as most of my machines I just disable Secure Boot, but it's an option if you know about it and buy carefully.
I see what you mean now, I screwed up reading your first comment.
Even though Secure Boot can be disabled on most hardware afaict [0] that's still a step consumers won't take so the point still stands easily. Especially with the amount of "you will break everything and kick a a puppy" that manufacturers throw in there to disuade anyone who manages to get to the menu.
[0] worked at a repair ahop until 1.5ish weeks ago, have disabled SB on a lot of hardware.
[1]: "On Ubuntu, all pre-built binaries intended to be loaded as part of the boot process, with the exception of the initrd image, are signed by Canonical's UEFI certificate, which itself is implicitly trusted by being embedded in the shim loader, itself signed by Microsoft.
On architectures or systems where pre-loaded signing certificates from Microsoft are not available or loaded in firmware, users may replace the existing signatures on shim or grub and load them as they wish, verifying against their own certificates imported in the system's firmware."
[1] https://wiki.ubuntu.com/UEFI/SecureBoot#How_UEFI_Secure_Boot...
And also, can’t you just disable Secure Boot?