Running Keystone Enclave on VF2

Has anyone managed to run Keystone Enclave on VF2?

Following this thread I have managed to boot : u-boot spl → opensbi (with Keystone’s security monitor) → u-boot proper but all the kernels that I have deployed keep panicking.

Moreover the opensbi must be signed at boot from a Root of Trust (RoT e.g. TPM, Sanctum) which I have not managed to do through u-boot spl.