Andreas (in CC) may have more up-to-date information about the possibility to get a shim for aarch64 signed with MS key.