official list is here: https://uefi.org/revocationlistfile
(I have my own root configured for all of my machines so only stuff I've signed can boot)