Oh, and that's not set up by the bootloader, it's in arch/x86/boot/compressed/eboot.c:
boot_params->secure_boot = get_secure_boot();
Oh, and that's not set up by the bootloader, it's in arch/x86/ boot/compressed /eboot. c: