Here are my questions again:
When is the OTPMK read during the secure boot process?
Also, what reads the OTPMK?
I'm just trying to understand what the OTPMK is for. The manuals just state to provision the OTPMK but don't discuss what part of the secure boot reads it and why the OTPMK exists in the first place.