In that case we probably have the answer already :) The next question then would have been whether secureboot-signing it yourself and replacing the PK/DB in the BIOS would have made it work, but it's really unfortunate that we've gotten to this point.