I guess the best solution is to ignore the error from import_mok_state() when Secure Boot is off so that we can at least work around the faulty firmware...