The user might not need to do anything, but it would be useful for the user to be able to find out, from Purism documentation (or from other documentation linked to by Puri.sm):
- how, from the BIOS TPM menu that you mentioned, to find out the “owner” and the public part of whichever certificate is currently “configured” in the TPM;
- how to generate a private key for use with the TPM;
- how to use the TPM to verify the next stage in the boot chain, to achieve the first stage of trusted boot.
Based on Kyle Rankin’s post on 28 February 2018, I guess that the plan is to provide that information ASAP.
Until that happens, any pointers to where drafts of that information can be found would be welcome.