Wonderful tool! I started using it since 0.6 because sbsigntools and pesign both choked on some EFI executables I had, but sbctl's go-uefi parser did not. It also seems to handle enrolling PK/KEK/db/dbx a lot more reliably than sbkeysync (which used to ignore errors and exit(0)) and efivar.