Debian now has a UEFI shim signed by the Microsoft UEFI CA to facilitate installations on Secure Boot - enabled systems. (Having the Microsoft UEFI CA Cert on board is optional for UEFI vendors though.)
(Via Firmware Security.)
(Via Firmware Security.)