Well, that theory didn’t last long. I attempted to install with TPM-backed encryption, which has Secure Boot as a hard requirement, but the installer then informed me that it must also be enabled (deployed mode). I checked with mokutil --sb and it was in setup mode, as intended.
In my search for Canonical’s signing certificate, I happened upon this:
It seems to contain info on how to do this manually, but I’ve only just started reading.