The issue is that both iPXE (ipxe.efi) and the FOS linux kernel (bzImage) are not signed. So secure booting is not supported natively by the FOG Project.
In contrast Ubuntu has a signed shim and grub kernel they use to jump start into the ubuntu linux kernel. If someone was a little skilled they could probably make iPXE and FOS boot using a similar shim.