"BAD signature from OEM Key" during Getting Started guide on new laptop

Just bought a purism laptop and I’m following the setup instructions to the letter https://docs.puri.sm/PureBoot/GettingStarted.html
I just finished the “Changing the TMP admin password” step (successfully I believe, it brought me back to main boot screen)
Now when I default boot it says:

gpg: BAD signature from "OEM Key (OEM-generated key) <...>" [ultimate]
Invalid signature on kexec boot params
!!!!!! Failed default boot
New value of PCR[4]: ...
!!!!!! Starting recovery shell
/boot #

What should I do?

Purism Support told me to do https://docs.puri.sm/PureBoot/GettingStarted.html#oem-factory-reset

I got the same problem after resetting the TPM again, turns out I needed to run Options -> Update checksums afterwards