Also a secure boot setup is much more difficult this way.
I for my part love the UKI. Never had a simpler boot setup!
Is it? Don't you just sign the bootable kernel image that already has the initrd and command-line built in?
Oh, I guess if you're using Microsoft as a CA I can see why that would be tricky.
In case of a UKI it's very simple of course. Just sign the boot image.
That's why I love the UKI. :-)