Earlier quoted context omitted.
The Windows 10 hardware certification permits the OEM to make Secure Boot not disablable. But the way the major distros work, they get a pre-bootloader signed with the Microsoft key through Microsoft's signing service, and that pre-bootloader contains a key permitting the chaining of the real bootloader, the kernel, signed with the distro key. So it's not a big problem.
Up till W8.1, the spec ( https://msdn.microsoft.com/en-us/library/windows/hardware/jj... ) explicitly requires the ability to disable Secure Boot: On non-ARM systems, the platform MUST implement the ability for a physically present user to select between two Secure Boot modes in firmware setup: "Custom" and "Standard". Custom Mode allows for more flexibility as specified in the following: ... B.If the user ends up de…
"The precise final specs are not available yet, so all this is somewhat subject to change, but right now, Microsoft says that the switch to allow Secure Boot to be turned off is now optional. Hardware can be Designed for Windows 10 and can offer no way to opt out of the Secure Boot lock down." http://arstechnica.com/information-technology/2015/03/window...