I came across an issue on a https://github.com/linux-surface/linux-surface/issues/906
I modified /etc/dkms/framework.conf to specify the "existing" certs that were generated by DKMS on Ubuntu:
# mok_signing_key=/var/lib/dkms/mok.key mok_signing_key="/var/lib/shim-signed/mok/MOK.priv" # mok_certificate=/var/lib/dkms/mok.pub mok_signing_key="/var/lib/shim-signed/mok/MOK.der"
Then I issued an
sudo update-secureboot-policy --enroll-key
gave it a password
and rebooted