If it's just for test, it would be fine to extract the "code" and "vars" files from ovmf in Factory and configure openQA to use the specific firmware files. BTW, for the incoming update of ovmf/edk2 201905stable, I'm planning to drop the key embedding patch and use the upstream EnrollDefaulyKeys.efi to generate the varstore with preloaded keys. So in the future, the keys will not be in the "code" files anymore but in the "vars" files.