Why Installing 2023 Secure Boot Certificates (manually) on HP Elitebook 840 G5 such a problem?


Thanks Steve. Tried the method described, unfortunately, no luck.

here is a link to the Microsoft secure boot 2023 certs that you can download and install manually
click the links on the page for the downloads to start.


edit to add the KEK downloads (the link is at the bottom of the linked page above)

and the GitHub Microsoft secure boot objects
with thanks to @garlin

give that a try to see if that corrects the problem.
best of luck Steve ..
 
Last edited:

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    Realtek External 5w speaker bar.
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned C:/D: drives.
    2x 1TB USB HDD External Backup/Storage.
    all VeraCrypt encrypted.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    Dell WiFi UK extended
    Mouse
    Dell WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Vivaldi Browser/Email/Calendar
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
Installing the other DB and DBX certs is secondary, until you've applied the KEK CA 2023 first. Once you have manually installed KEK CA 2023, the Secure Boot task can take over and finish the work. You only need to install the one cert that is blocking the update.

This is true for every unsupported PC out there.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Under Secure Boot Management options are: Import Custom Secure Boot Keys, Clear Secure Boot Keys, Reset Secure Boot Keys to factory default, and Enable MS UEFI CA key(which is checked already), but all these options are grayed out. Also says: "Access to the above settings requires Sure Start Secure Boot Keys Protection to be disabled." Last entry says: "Requires BIOS Administrator credentials to be configured and Secure Boot enabled."
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
What you see follows our expectations.

1. Disable BitLocker on drive C: if it's enabled. This step is very important, otherwise you can be locked out of Windows if you don't have the recovery key printed out, or a recovery file saved to an USB drive. It's simpler to disable BitLocker before proceeding.

2. Download the ZIP file from this thread, and run this command:
garlin's PowerShell scripts for updating Secure Boot CA 2023

Code:
Update-UEFI.bat

3. Shutdown Windows. Create an Admin password in the BIOS. Write it down so you don't forget later.

3. Disable Sure Start protection.

4. Under "Import Custom Secure Boot Keys", look for a KEK category. You will be asked to search a list of disk devices for the file to import. The script copied the cert file to the \EFI folder. Browse each of the devices until you see a folder named \EFI. Under \EFI will be a "Certs" folder. Inside that folder should be the file to import.

You might see multiple copies of the KEK CA 2023 file. They're all the same, but renamed differently because some BIOS'es are picky about the required file extension.

5. If the file is successfully imported, restart Windows.

6. Run the update script again.
Code:
Update-UEFI.bat

7. Now you can enable Secure Boot mode. Leave Sure Start disabled.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
You said leave Sure Start off. For how long?? Isn't it required when starting up??
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
No. Sure Start is an anti-tampering mechanism. It looks for recent Secure Boot changes in the UEFI and reverts from a hidden backup copy of the settings. Sure Start provides no other functionality once Windows (or any OS) has booted past the BIOS.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Sorry to be such a "noob", but, I'm unsure about disabling sure start. There are several categories are ready checked. 1. Dynamic Runtime Scanning of Boot Block, 2. Sure Start Boot Keys Protection, 3. Enhanced Firmware Runtime Intrusion Prevention ans Detection. Sure Start Bios Settings Protection is unchecked. Do I unchecked everything that's checked?? Don't want to make a mistake.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
All of them.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Well, I must have done something wrong. Get an error that boot device not found. Error 3FO. Guess I'll have to reinstall Windows. Maybe this was not for me.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
Secure Boot is off, right? Did you add the KEK cert file or not? None of these steps should prevent the PC from booting.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
From the HP support site:
To restore the BIOS default setting, open the BIOS Setup screen.
  1. Turn off the computer and wait five seconds.
  2. Press the power button to start the computer and repeatedly press the f10 key to enter the BIOS setup menu.
  3. On the BIOS Setup screen, press f9 to select and load the BIOS Setup Default settings.
  4. Press f10 to Save and Exit.
  5. Use the arrow keys to select Yes, and then press Enter when asked Exit Saving Changes?
  6. Follow the prompts to restart your computer.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Honestly, I didn't see a way to add the KEK file, so I put everything back like it was. That's when I started getting the error.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
Honestly, I didn't see a way to add the KEK file, so I put everything back like it was. That's when I started getting the error.

Boot back into the bios and slowly review the sections you were in and what changes you made. Worst case scenario, you can reset the bios back to its default state, you'll find that option in the bios.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Reviewed all the sections I changed and changed back. Error F30 appeared. Only setting that logs into Windows is Legacy enabled, Secure Boot disabled. Before it was: Legacy disabled, Secure Boot enabled. But using that setting causes the F30 error....No boot device found. I'm at a loss. I don't have any idea what to do next.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
The Error 3F0 (often read as 3FO) on an HP computer means "Boot Device Not Found". Your computer cannot find the hard drive or SSD with Windows on it. This happens due to a loose physical connection, wrong BIOS settings, or a broken storage drive.

Reset BIOS defaults see it helps also try to Check boot order.
 

My Computer My Computer

At a glance

Windows 11AMD Ryzen 7 5700GMicron Technology DDR4-3200 16GBNVIDIA GeForce RTX 3060
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
HP Pavilion
CPU
AMD Ryzen 7 5700G
Motherboard
Erica6
Memory
Micron Technology DDR4-3200 16GB
Graphics Card(s)
NVIDIA GeForce RTX 3060
Sound Card
Realtek ALC671
Monitor(s) Displays
Samsung SyncMaster U28E590
Screen Resolution
3840 x 2160
Hard Drives
SAMSUNG MZVLQ1T0HALB-000H1
Reviewed all the sections I changed and changed back. Error F30 appeared. Only setting that logs into Windows is Legacy enabled, Secure Boot disabled. Before it was: Legacy disabled, Secure Boot enabled. But using that setting causes the F30 error....No boot device found. I'm at a loss. I don't have any idea what to do next.

Run the check script:
Code:
Check-UEFI.bat -Verbose
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I have tried and tried to resolve the f30 error on my hp elitebook 840 g5, without any success. I was able to boot Windows normally by changing the Legacy and Secure boot supports to disabled. I would rather have Secure Boot enabled, but, the f30 error prevents that from happening. I would just like a clear, concise way to eliminate the error and be able to use Secure Boot. Any help would be greatly appreciated.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
I don't think there's a fix other than HP releasing a new firmware. That's probably why HP didn't bother to just share a signed KEK CA 2023 with MS, because you still would have encountered a BIOS problem.

The best you can do is to try:
1. CSM is disabled. Secure Boot is enabled. But don't boot.
2. Reset Secure Boot settings.
3. Secure Boot is disabled.
4. Try to reboot Windows twice in a row (if it works).
5. Enable Secure Boot.

Since there's a firmware bug, it doesn't know how to get itself out of trouble. Some BIOS'es are more fortunate, and the above sequence can sometimes "kick" it back to a known good state. Other times, it's stuck that way unless you can reflash the BIOS again.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Can BIOS be reflashed? Or is that wishful thinking? Current bios is:HPQ78 v. 01.31.00. Just wondering?
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
There's no newer BIOS. I dunno if your HP will allow the same BIOS to be reflashed again. Some BIOS'es don't support it (must be newer).
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7

Latest Support Threads

Back
Top Bottom