Enable UEFI Secure Boot for bookworm+ on arm64
This is functional according to most recent wiki entry https://wiki.debian.org/SecureBoot#arm64_problems and this looks good from my tests. Currently, the image ends up with unsigned grub as in the removable media EFI path instead of signed shim. Should be no changes from this for non-SB systems.