Hot take: MS 3rd party UEFI CA should not exist at all. Bought an AMD GPU? Enroll an AMD key. Want to install Linux? Enroll the distro key instead of the mess with shims. Making a proper CA system then just signing everything with one key is just stupid.

