Why Installing 2023 Secure Boot Certificates (manually) on HP Elitebook 840 G5 such a problem?


Thanks Steve. Tried the method described, unfortunately, no luck.

here is a link to the Microsoft secure boot 2023 certs that you can download and install manually
click the links on the page for the downloads to start.


edit to add the KEK downloads (the link is at the bottom of the linked page above)

and the GitHub Microsoft secure boot objects
with thanks to @garlin

give that a try to see if that corrects the problem.
best of luck Steve ..
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    RealTek
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned.
    2x 1TB USB HDD External Backup/Storage.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    HP WiFi UK extended
    Mouse
    HP WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Edge & Firefox
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
Installing the other DB and DBX certs is secondary, until you've applied the KEK CA 2023 first. Once you have manually installed KEK CA 2023, the Secure Boot task can take over and finish the work. You only need to install the one cert that is blocking the update.

This is true for every unsupported PC out there.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Under Secure Boot Management options are: Import Custom Secure Boot Keys, Clear Secure Boot Keys, Reset Secure Boot Keys to factory default, and Enable MS UEFI CA key(which is checked already), but all these options are grayed out. Also says: "Access to the above settings requires Sure Start Secure Boot Keys Protection to be disabled." Last entry says: "Requires BIOS Administrator credentials to be configured and Secure Boot enabled."
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
What you see follows our expectations.

1. Disable BitLocker on drive C: if it's enabled. This step is very important, otherwise you can be locked out of Windows if you don't have the recovery key printed out, or a recovery file saved to an USB drive. It's simpler to disable BitLocker before proceeding.

2. Download the ZIP file from this thread, and run this command:
garlin's PowerShell scripts for updating Secure Boot CA 2023

Code:
Update-UEFI.bat

3. Shutdown Windows. Create an Admin password in the BIOS. Write it down so you don't forget later.

3. Disable Sure Start protection.

4. Under "Import Custom Secure Boot Keys", look for a KEK category. You will be asked to search a list of disk devices for the file to import. The script copied the cert file to the \EFI folder. Browse each of the devices until you see a folder named \EFI. Under \EFI will be a "Certs" folder. Inside that folder should be the file to import.

You might see multiple copies of the KEK CA 2023 file. They're all the same, but renamed differently because some BIOS'es are picky about the required file extension.

5. If the file is successfully imported, restart Windows.

6. Run the update script again.
Code:
Update-UEFI.bat

7. Now you can enable Secure Boot mode. Leave Sure Start disabled.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
You said leave Sure Start off. For how long?? Isn't it required when starting up??
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
No. Sure Start is an anti-tampering mechanism. It looks for recent Secure Boot changes in the UEFI and reverts from a hidden backup copy of the settings. Sure Start provides no other functionality once Windows (or any OS) has booted past the BIOS.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Sorry to be such a "noob", but, I'm unsure about disabling sure start. There are several categories are ready checked. 1. Dynamic Runtime Scanning of Boot Block, 2. Sure Start Boot Keys Protection, 3. Enhanced Firmware Runtime Intrusion Prevention ans Detection. Sure Start Bios Settings Protection is unchecked. Do I unchecked everything that's checked?? Don't want to make a mistake.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
Well, I must have done something wrong. Get an error that boot device not found. Error 3FO. Guess I'll have to reinstall Windows. Maybe this was not for me.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
Secure Boot is off, right? Did you add the KEK cert file or not? None of these steps should prevent the PC from booting.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
From the HP support site:
To restore the BIOS default setting, open the BIOS Setup screen.
  1. Turn off the computer and wait five seconds.
  2. Press the power button to start the computer and repeatedly press the f10 key to enter the BIOS setup menu.
  3. On the BIOS Setup screen, press f9 to select and load the BIOS Setup Default settings.
  4. Press f10 to Save and Exit.
  5. Use the arrow keys to select Yes, and then press Enter when asked Exit Saving Changes?
  6. Follow the prompts to restart your computer.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Honestly, I didn't see a way to add the KEK file, so I put everything back like it was. That's when I started getting the error.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
Honestly, I didn't see a way to add the KEK file, so I put everything back like it was. That's when I started getting the error.

Boot back into the bios and slowly review the sections you were in and what changes you made. Worst case scenario, you can reset the bios back to its default state, you'll find that option in the bios.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Reviewed all the sections I changed and changed back. Error F30 appeared. Only setting that logs into Windows is Legacy enabled, Secure Boot disabled. Before it was: Legacy disabled, Secure Boot enabled. But using that setting causes the F30 error....No boot device found. I'm at a loss. I don't have any idea what to do next.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
The Error 3F0 (often read as 3FO) on an HP computer means "Boot Device Not Found". Your computer cannot find the hard drive or SSD with Windows on it. This happens due to a loose physical connection, wrong BIOS settings, or a broken storage drive.

Reset BIOS defaults see it helps also try to Check boot order.
 

My Computer My Computer

At a glance

Windows 11AMD Ryzen 7 5700GMicron Technology DDR4-3200 16GBNVIDIA GeForce RTX 3060
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
HP Pavilion
CPU
AMD Ryzen 7 5700G
Motherboard
Erica6
Memory
Micron Technology DDR4-3200 16GB
Graphics Card(s)
NVIDIA GeForce RTX 3060
Sound Card
Realtek ALC671
Monitor(s) Displays
Samsung SyncMaster U28E590
Screen Resolution
3840 x 2160
Hard Drives
SAMSUNG MZVLQ1T0HALB-000H1
Reviewed all the sections I changed and changed back. Error F30 appeared. Only setting that logs into Windows is Legacy enabled, Secure Boot disabled. Before it was: Legacy disabled, Secure Boot enabled. But using that setting causes the F30 error....No boot device found. I'm at a loss. I don't have any idea what to do next.

Run the check script:
Code:
Check-UEFI.bat -Verbose
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

Latest Support Threads

Back
Top Bottom