Anybody have a guide on using secure boot? 

I managed to set /usr/share/edk2/ovmf/OVMF_CODE.secboot.fd as the <loader readonly='yes' type='pflash'>, but when I change this windows only shows me a black screen.

I've also tried to fiddle with the following two settings: <type arch='x86_64' machine='pc-q35-2.10'>

I'm running fedora 27.

Any advice on how to implement secure boot for a VM under KVM/Virt-Manager/qemu/etc etc. 

I found this https://en.opensuse.org/openSUSE:UEFI_Secure_boot_using_qemu-kvm but it doesn't seem to match up with what I'm seeing on a few different aspects, (obviously of which, is I'm not using SuSE)

Anyway, any help at all on this would be greatly appreciated.

Thanks!
-frizop