I took a quick look at the code and I'm not seeing the usual steps for certificate management, although I may have missed it.
Since shim is an executable in the ESP, which is a HDD or SSD partition, the space constraints are more relaxed (it's not a small SPI NAND chip).
On the other hand, I don't think it's practical to actually implement HTTPS properly in UEFI, since you'd have to constantly update the trust store, and you'd have to have actual internet access to be be able to check the certificate revocation lists (otherwise, you are vulnerable to surreptitious malicious activity from otherwise trusted CAs).
That's not true. It's significantly easier to ensure the security of an offline signing key than it is to ensure that an arbitrary HTTPS server avoids ever becoming compromised.