Hi Michal,
If you have a board with TPM just simply go with vboot + measured boot. It will automatically extend the loaded parts of coreboot before execution.
Which configs are needed?
CONFIG_VBOOT CONFIG_VBOOT_MEASURED_BOOT
Anything else?
Thanks!