New secureboot keys to sign Unified Kernel Images were created: https://issues.redhat.com/browse/SIGNSERVER-416 so we need to include them into 'redhat-sb-certs' package. For RHEL9.3+, I suggest we create /usr/share/pki/sb-certs/secureboot-uki-virt-x86_64.cer and /etc/pki/sb-certs/secureboot-uki-virt-x86_64.cer link containing secureboot504.
For CentOS Stream, we need to package centossecureboot204. I can create a separate BZ if needed.
We will get to this next sprint, which starts next week.