In contrary to @next_to_utter_chaos (here: Secure Boot and Expiring Microsoft Keys - #4 by next_to_utter_chaos ) I am not offered the new keys.
And they are not yet there as this commands does not return anything:
sudo efi-readvar -v db | grep "UEFI CA 2023"
I just can confirm existence of the old 2011 keys:
└─▶ $ sudo efi-readvar -v db | grep 2011
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011
Yesterday my OS (KDE Neon noble amd64) got a BIOS update:
System Firmware (0.0.3.5 → 0.0.3.18)