boot fails after OEM factory reset, refresh TOTP/HOTP, update checksums and sign all files in /boot
gpg BAD signature from OEM Key
Invalid signature on kexec boot params
failed default boot
Any advice on where to look to understand this process better would be much appreciated.