If sbctl tool is used, this is no longer necessary, since sbctl can now enroll builtin firmware keys. We just have to do these steps:
- Enter secure boot setup mode. See Secureboot setup mode - #25 by ROBIN_Benjamin
- Enroll your own keys (including Microsoft keys and Framework firmware keys) using
sbctl enroll-keys -m -f