From this comment: Secure Boot support for UEFI BSD mpt3x64.rom · Issue #9 · EverLand1/9300-8i_IT-Mode · GitHub
I noticed that Supermicro apparently provides Microsoft (Secure Boot) signed drivers/firmware.
https://www.supermicro.com/wdl/driver/SAS/Broadcom/
You can download all the files quickly with this command:
wget --recursive --no-parent --convert-links --timestamping --directory-prefix=supermicro https://www.supermicro.com/wdl/driver/SAS/Broadcom/
Does anybody now if these is are the “normal” unmodified firmware that should just work on any machine / OS?