Just throwing this in. You might want to encorporate Shim in order to support both UEFI and Secure Boot. It's been around since 2012 and I don't know if this was already something you guys considered, but it's worth a look if not.
↧