Until VirtualBox implements TPM 2.0 pass through, which they've already started working on: https://www.virtualbox.org/changeset/90946/vbox Qemu already supports TPM pass through and secure boot.
I fear that might not be a good thing. Wouldn't it be better and safer to just emulate TPM in the VM?
Edit: autocorrect TPM