debian: update build and packaging from Debian upstream Among other thing this now ships OVMF code/vars with secureboot and MS keys enrolled, allowing Win11 final to get installed and secure boot support in general. Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>