At the moment the best options are:
- rotate online signing key
- build new shim with old signing key in vendorx (revoked ESL)
- build new kernels with old signing key built-in revoked keyring
This is to ensure that old shim & old kernel can boot or kexec new kernels.
To ensure new shim cannot boot old kernels.
To ensure that new kernels cannot kexec old kernels.
This is revocation strategy used by Canonical Kernel Team for Ubuntu Kernels.
There is no sbat for kernels yet (and/or nobody has yet started to use sbat for kernels).