https://bugzilla.redhat.com/show_bug.cgi?id=1322076
--- Comment #6 from Stephen Wadeley swadeley@redhat.com --- Re this bit:
~]# keyctl list %:.system_keyring 5 keys in keyring: ...asymmetric: Microsoft Windows Production PCA 2011: a92902398e16c497... ...asymmetric: Fedora kernel signing key: ba8e2919f98f3f8e2e27541cde0d... ...asymmetric: Fedora Secure Boot CA: fde32599c2d61db1bf5807335d7b20e4... ...asymmetric: Red Hat Test Certifying CA: 08a0ef5800cb02fb587c12b4032... ...asymmetric: Microsoft Corporation UEFI CA 2011: 13adbf4309bd82709c8...
The above output shows the addition of two keys from the UEFI Secure Boot "db" keys plus the Fedora Secure Boot CA which is embedded in the shim.efi boot loader
the description, or explanation, is not very clear.