snakeoil/OVMF_VARS.snakeoil.fd might not match OVMF_CODE.secboot.fd we use in tests.
Here are some ways we could handle it:
- Use
lockdown.efi from efitools to install snakeoil keys on any OVMF_VARS.fd
- Put the snakeoil keys as well as code and variables images for OVMF in a separate repo.