Coreboot questions

What forms of FDE work well? can this work with opal compliant disks? can the disk be encrypted within coreboot itself?

can one of the internal drives be disabled from within coreboot?

also, stupid questions because ive never used coreboot, but in the past, ive been bitten by stupid things i thought “obviously” should work/be included

can you password protect changes to coreboot configuration like you can with any other bios?
can you password protect booting at all?
does the iommu (vt-d) work with qubes-os?