Add signature checking for grub.cfg (instead of just the EFI shim) but that requires enrolling a local key
Add initrd signatures to grub.cfg