Due to changes in the secure boot summarized in https://wiki.debian.org/SecureBoot/CAChanges)
there needs to be an upgrade to a newer fwupd version in bookworm to allow updating the trust
chain.
This work is tracked by release team in the bookworm-pu bug:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139252
Unfortunately; upgrading to the newer fwupd version requires an ABI bump which means some minor
patches for the ABI change and rebuilding against the newer libfwupd.
I've validated this works properly, and I would like permission to send up a NMU coordinating
with the updated fwupd. The proposed debdiff is attached to the release team bug.