Firmware Interface Table

BIOS Specification October 2022 Revision 1.4

ID 599500
Date 10/01/2022
Intel Confidential
Document Table of Contents

Vendor Authorized Boot Key Manifest (Type 0x1B) Rules

VAB Key Manifest (Type 0x1B) entry in the FIT is required only for platforms which support Vendor Authorized Boot. It is signed by the Key Authorization Key (KAK). The VAB Key Manifest contains keys that sign VAB Image Manifest (Type 0x1C). There can only be zero or one Type 0x1B record present in the FIT.

  1. The Version field should be set to 0x0100.
  2. The C_​V bit in this entry should be clear
  3. The Checksum field is set to 0.
  4. The entry must be 64 byte aligned.
  5. Address + size must be under (4GB – 1) and above (4GB – 16MB)