So I just worked through trying to make #Debian bookworm do hibernation with encrypted swap and #SecureBoot. Looks like #Linux is fine with using a swap file from an encrypted partition, but now the requirement is apparently that the swap is signed to prevent modification. I stuck what I know here https://wiki.debian.org/Hibernation#UEFI_.2F_Secure_Boot
Going to my #BIOS and disabling "Block Sleep (S3)" makes this promising message show up in the #kernel logs: "Low-power S0 idle used by default for system suspend"