Secure boot can always enabled after installation of ESXi and adding "needed" 3rd Party VIBs because there is a test function available to identify vibs without a valid signature/certificate.
/usr/lib/vmware/secureboot/bin/secureBoot.py -c
If you pass that step you can easily enable secure boot within the Server BIOS/Setup during a reboot.
Regards,
Joerg