The answer is no to all of them, at least if you deal with hardware that... wants to pass Microsoft certification checks.
Because one of them requires ability of device owner to delete any pre-existing platform keys and load their own set.
Because one of them requires ability of device owner to delete any pre-existing platform keys and load their own set.
On x86 based systems.
My understanding is that Arm systems require the opposite.
If you don't mind me asking, how did you get into embedded development? I'm trying to sample various types of development and see what I enjoy, and embedded development seems quite interesting to me though I've never done more than an arduino.
(And I include ostensibly FLOSS in it as well, as shitty firmware can be worse than no firmware)