+# By default Secure Boot is enabled using the approach from Ubuntu.
+# Currently only the Ubuntu approach is supported, which is restricted
+# to loading Linux kernels and using a minimal version of GRUB.
+# If unset defaults to "ubuntu"
+# SECURE_BOOT='disable' # do not enable Secure Boot
+# SECURE_BOOT="ubuntu" # use approach from Ubuntu
+