Secure boot

Hi !
Is it possible for myself to build a secure linux kernel and use it with
Debian ?
Or does the list of key signing authority fixed inside the EFI bios ?
