Bug#820036: No bug mentioning a Debian KEK and booting use it.
ard lacks the KEK the shim needs .Of course this does not stop users making their own PK and KEK set latter and it not against the rules to-do this. Peter Dolding
Bug#820036: Key replacement and revocation
replaced. So that a person who has left is not walking around with a master key. How is this going to be performed is a very serous consideration. Peter Dolding