Streamlining secure boot for 26.10

I think @mkukri meant /boot/efi/grub/grub.cfg which is not measured, IIUC. There’s also always the possibility of simply editing the menu entry from the boot menu itself. And before you demand it be locked down think about the last time you messed up and needed to live-fix the kernel command line to even be able to boot.