Allow for shim-only secure UEFI boot
When grub-efi-amd64-signed and grub-common have mismatched dependencies (e.g. due to binNMUs), allow a shim-only secure boot. The user has to enroll the hash of the EFI/boot/grub*.efi file and then secure booting can continue. Shim-only is supported only for '--uefi-secure-boot=auto'