How to set up Boot Guard on a Manufacturing Mode enabled BIOS?

Could someone please describe how to set up Boot Guard on a Manufacturing Mode enabled BIOS?

I’ve been researching the topic and come up with a few resources that sort of explain it. I’m trying figure out what needs to be signed, how to make a manifest, and how to then put it all together.


The guide on this site touches on the topic for CSME 12:

[Guide] Clean Dumped Intel Engine (CS)ME/(CS)TXE Regions with Data Initialization



What if you made your own Private RSA Key and signed the firmware? Would that do it?


This site describes how an attacker could take advantage of an unlocked Boot Guard, which seems like maybe sort of same way one could program their own Boot Guard?

Who Watch BIOS Watchers?



I guess I’m wondering if I’m on the right track and if anyone can help shed some light on what steps to take for this process?


I found this PDF Guide from Intel:

http://support.prosys.ro/Theon/Theon_470…Rev%201%201.pdf



This mentions Secure Boot, but is Boot Guard the same process?