My pull request that backported unified Xen executables was merged into Qubes for the upcoming 4.1 release. This will make it possible to enable UEFI SecureBoot on a stock Qubes install (with a bit of additional glue that is yet to be written) https://github.com/QubesOS/qubes-vmm-xen/pull/89
@th Cool!
@th oooh shiny!