Installing keys is part of flashing an image (and should remain), but it would be convenient to have the option to explicitly install, update, or delete Secure Boot keys outside of the image flash process. (Note: to delete keys, we would need to include additional secure boot keys, which may be relegated to an admin-only vx-iso release rather than the more general release.)