Current working is any update of secure variable completely replaces the previous value. For example, if the KEK currently contains the ESL's X, Y and Z then using secvarctl or writing to the sysfs locations to update the KEK with a new auth file containing the ESL's A and B will set the updated KEK to just contain A and B . So, appending and removing specific entries is currently not supported.
This is the request for feature/enhancement to support append/remove of specific entries from the secure variables.
Thank you.