Hi, I am running secureblue on a Thinkpad notebook. I had no issues installing Fedora Atomic with Secureboot and the same applies for secureblue (easy transition + I ran the ujust script for enrolling the secureblue key). I enabled the BIOS option for Secureboot and allowing alternative OS keys.
All looks good in fwupdmgr results - except for the one-time programmable Intel Bootguard lock. Intel Bootguard displays as active, the ACM protection shows enabled too. What is wrong?