* Support UEFI Secure Boot (LP: #1075181): - Try to install a signed kernel if base-installer asks for one, and don't leave signed kernels installed if it doesn't. - If the SecureBoot EFI variable is set, then ensure that grub-efi-amd64-signed and shim-signed remain installed. - Copy the signed kernel from /cdrom if it is not in the squashfs. If there is a signed kernel there but no unsigned one, then use sbattach to remove the signature and construct the unsigned kernel on the fly.