The efitools [1] recipe seems to be a good candidate for the oe-core or meta-oe layer as it is a dependency of more and more bsp's to implement uefi secure boot.
[1] https://github.com/Wind-River/meta-secure-core/tree/master/meta-efi-secure-boot/recipes-bsp/efitools.