Secure Boot Manual Logo Test

This test verifies the proper functioning of boot time image authentication and the proper authentication and operation of UEFI secure boot variable updates. This test should be performed two times by using two different configurations.

  • Configuration A - EFI USB is first in the boot order.

  • Configuration B - EFI USB is last in the boot order.

Test details

   
Specifications
  • System.Fundamentals.Firmware.UEFISecureBoot
Platforms
  • Windows 10, client editions (x86)
  • Windows 10, client editions (x64)
  • Windows Server 2016 (x64)
Supported Releases
  • Windows 10
  • Windows 10, version 1511
  • Windows 10, version 1607
  • Windows 10, version 1703
  • Windows 10, version 1709
  • Windows 10, version 1803
  • Windows 10, version 1809
  • Windows 10, version 1903
  • Next update to Windows 10
Expected run time (in minutes) 90
Category Compatibility
Timeout (in minutes) 60
Requires reboot false
Requires special configuration true
Type manual

 

Additional documentation

Tests in this feature area might have additional documentation, including prerequisites, setup, and troubleshooting information, that can be found in the following topic(s):

Running the test

Before you run the test, complete the test setup as described in the test requirements: WDTF System Fundamentals Testing Prerequisites.

This test requires special firmware (debug firmware) on Windows W RT systems that allows you to clear secure boot keys and turn off secure boot. On non-Windows RT systems, a firmware menu should allow you to perform these actions.

Before you run the test:

  1. Clear all Secure Boot variables.

  2. Set the following registry entries:

reg add HKLM\System\CurrentControlSet\Services\iospy\StartOverride /v 0 /t REG_DWORD /d 3 /f
reg add HKLM\System\CurrentControlSet\Services\MSDMFilt\StartOverride /v 0 /t REG_DWORD /d 3 /f
  1. Make sure that you can set the system under test (SUT) to boot from the USB first. If you cannot make this setting, you must manually boot into the different USB sticks when you are instructed to do so.

  2. You must have two USB flash drives.

When it runs, the test installs UEFISecureBootManualTests.zip on the system under test (SUT). Review the README.TXT file in the zip file for further instructions.

The test operator must respond to the test prompts.

The following certificates are required if they aren't present on the machine:

Troubleshooting

For generic troubleshooting of HLK test failures, see Troubleshooting Windows HLK Test Failures.

For troubleshooting information, see Troubleshooting the Windows HLK Environment.

This test returns Pass or Fail. To review test details, review the test log from Windows Hardware Lab Kit (Windows HLK) Studio.