it really depends what youre protecting against, rootkits are a thing and secure boot would protect against that, so as long as you dont keep the private key in the same system, otherwise defeats the purpose, on my arch install i use sbctl, but its dumb, the kernel needs tk be resigned on every update, meaning i need the key stored in my pc, which some malicious actor could just use that to sign their rootkit