You want to multi-boot many distributions.
You can click the Boot tab and then scroll down to around the middle of the option list (which is likely to scroll—note the scroll bar in the screen shot) where you'll see an item called Secure Boot, as shown below.
This won't be necessary if you're using elilo, grub Legacy, or some versions of grub 2 to launch Linux kernels, but you may need to enroll a hash for a chainloaded boot loader launched from grub.
To enter it, you can hit the FnF2 key as the computer boots.
Secure Boot, though, is designed to add a layer of protection to the pre-boot process.Before conversion we strongly recommend to copy all critical data to the external drive.When you're done, press FnF10 to save the change and exit.Stock versions of elilo, grub Legacy, and older builds of grub 2 don't check Secure Boot status or use EFI system calls to load kernels, so even signed versions of these programs will launch any kernel you feed them.

So, booting of any (both 32- and 64-bit!) Windows version in bios-based systems without EFI is supported.
Replacing your firmware's keys doesn't take much more effort than using Shim if you would need to sign your own binaries for some reasonsay, if you're using a distribution such as Gentoo that doesn't provide pre-signed binaries.
When trying to install Windows to a GPT disk in a PC without UEFI firmware, the Windows Installer returns an error: "Windows cannot be installed to this disk—the selected disk is of the GPT Partition Style." This tool cannot guarantee that such partitions will remain bootable after conversion. MokManager will ask for verification that you want to enroll the key. Sometimes another option must be set before this can be done, though; and sometimes names vary enough to create confusion.