recently ran into this realization with @j0rge that we don't actually sign upstream provided modules in our kernel-cache, only the kernel (vmlinuzvmlinuz binary)...
TL;DR - if I succeed, this will enable secureboot for Bluefin LTS HWE and a potential uCore with LTS kernel (assuming the installation of our ublue MOK)