UEFI 2.4 has been out for a while (18 months to be exact). However, it’s taken me a while to redo the tianocore builds for the 2.4 base. This is now done, so the OVMF packages are now building 2.4 roms
https://build.opensuse.org/package/show/home:jejb1:UEFI/OVMF
Please remember that this is bleeding edge. I found a few bugs while testing the tools, so there are likely many more lurking in there. I’ve also updated the tools package
https://build.opensuse.org/package/show/home:jejb1:UEFI/efitools
As of version 1.5.1, there’s a new generator for hashed revocation certificates and KeyTool now supports the timestamp signature database. I’ve also published a version of sbsigntools
https://build.opensuse.org/package/show/home:jejb1:UEFI/sbsigntools
Which, as of 0.7, has support for multiple signatures.