Securing an Arch Linux Install

@mbernhard Yes, the dracut hook makes sure dracut signs the UEFI bins it generates. However I have not yet gone for this since I’m not sure how to re-enroll the framework KEK and DB to allow for firmware updates later.