this should ensure that a shim-signed package from a non-Proxmox repository
cannot overtake ours, even if the version is newer. since
proxmox-secure-boot-support is optional, this is entirely opt-in.
Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>