Why Installing 2023 Secure Boot Certificates (manually) on HP Elitebook 840 G5 such a problem?


There's no newer BIOS. I dunno if your HP will allow the same BIOS to be reflashed again. Some BIOS'es don't support it (must be newer).

HP will allow the same BIOS to be re-applied but wont allow you to downgrade the BIOS to a lower version.

i have just upgraded the BIOS on mine and my wifes systems
from H22 to H23 for my system (24ck x000)
and H32 to H33 on my wifes system (24ca x000)

once done there seems to be no way back to the older BIOS
both systems are running just fine with the new BIOS update.

best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    Realtek External 5w speaker bar.
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned C:/D: drives.
    2x 1TB USB HDD External Backup/Storage.
    all VeraCrypt encrypted.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    Dell WiFi UK extended
    Mouse
    Dell WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Vivaldi Browser/Email/Calendar
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
Hey Guys, I'm still dealing with this f30 error on my HP Elitebook 840 G5. I have abandoned the installing of 2023 certificates and just want to solve this problem. If any one have any concrete guidance to resolve this error. Please hit me up. I am able to boot into Windows, with Legacy and Secure boot supports disabled. Thanks in advanced.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
Your only hope is to follow some of the online hints on forcing your HP to reflash the same BIOS image again.

Usually you disable BitLocker first, download the spxxxxx.exe update file from HP, and run some Windows command-line or power-up key sequence to get it to read from an USB drive. I don't have this model, so my knowledge stops about there. The expectation is when it rewrites the BIOS, it won't save the currently corrupted NVRAM values in the same way it's done now. Which gets you out of the error mode.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
One question, would using BCD fix, rebuild solve the f30 error? Or applying default bios settings? Just asking. Thanks.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
Hello. I have been dealing with an f30 error on my HP Elitebook 840 G5. I have tried several suggested solutions I picked up from the Net. They don't seem to work. I tried to manually install the 2023 Secure Boot certificates a few weeks ago, without success. Now I get this f30 error whenever I enable Secure Boot. Laptop will Boot up to Windows, but, only if Legacy and Secure Boot supports are disabled. I want to able to enable Secure Boot for security. Can someone please help with this??? Thanks.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
No. The f30 error is from the BIOS itself, reporting it has corrupted NVRAM data. The BIOS knows how to check if the Secure Boot variables are intact by running a self-test on the stored certs.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
boot error f30 is normally the system cant find the boot device

can you make a bootable Linux live USB to boot from to check the system from a live environment
this wont install anything to your system but it will be able to check your hardware including any installed drives.

note
if you use bitlocker please unencrypt your drives and disable bitlocker for the time being.
best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    Realtek External 5w speaker bar.
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned C:/D: drives.
    2x 1TB USB HDD External Backup/Storage.
    all VeraCrypt encrypted.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    Dell WiFi UK extended
    Mouse
    Dell WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Vivaldi Browser/Email/Calendar
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
boot error f30 is normally the system cant find the boot device
In this case it's from the BIOS...

 

My Computer My Computer

At a glance

Windows 11 Pro 26H2
OS
Windows 11 Pro 26H2
Computer type
Laptop
Manufacturer/Model
Toshiba
Antivirus
Defender
In this case it's from the BIOS...


most likely but i wish to eliminate hardware problems first
then move on to BIOS and secure boot updates, especially manually updating the system.

disabling bitlocker will assist in both if it is enabled.
best of luck Steve ..
 

My Computers My Computers

  • At a glance

    Windows 11 HomeRyzen 7 5825u64GB DDR4 3200Ryzen 7 5825u
    OS
    Windows 11 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP 24" AiO
    CPU
    Ryzen 7 5825u
    Motherboard
    HP
    Memory
    64GB DDR4 3200
    Graphics Card(s)
    Ryzen 7 5825u
    Sound Card
    Realtek External 5w speaker bar.
    Monitor(s) Displays
    24" HP AiO
    Screen Resolution
    1920 x 1080 @60 Hz
    Hard Drives
    1TB WD Blue SN580 M2 SSD Partitioned C:/D: drives.
    2x 1TB USB HDD External Backup/Storage.
    all VeraCrypt encrypted.
    PSU
    90W external power brick
    Case
    24" All in One
    Cooling
    Default Air Cooling
    Keyboard
    Dell WiFi UK extended
    Mouse
    Dell WiFi 3 Button
    Internet Speed
    1GB full fibre
    Browser
    Vivaldi Browser/Email/Calendar
    Antivirus
    AVG Internet Security/Windows Defender
    Other Info
    Mainly Open Source Software
  • At a glance

    Ubuntu 22.04.5 LTSi5 7200u16GB DDR4Intel
    Operating System
    Ubuntu 22.04.5 LTS
    Computer type
    Laptop
    Manufacturer/Model
    Dell 13" Latitude 2017
    CPU
    i5 7200u
    Motherboard
    Dell
    Memory
    16GB DDR4
    Graphics card(s)
    Intel
    Sound Card
    Intel
    Monitor(s) Displays
    13" Dell Laptop
    Hard Drives
    250GB Crucial 2.5" SSD
    Mouse
    Generic WiFi 3 button
    Internet Speed
    WiFi only
    Browser
    Firefox
    Antivirus
    ClamAV TK
    Other Info
    Mainly Open Source Software
garlin's diagnosis was pretty clear.

The OP should stick to one thread for the same issue...
 

My Computer My Computer

At a glance

Windows 11 Pro 26H2
OS
Windows 11 Pro 26H2
Computer type
Laptop
Manufacturer/Model
Toshiba
Antivirus
Defender
Ran system diagnostics, ssd, memory, processor, tpm 2.0 all check out good (passed). If it's the BIOS itself, I have changed secure boot support options, reset secure boot to factory defaults, still no change in f30 error. What can I do now???
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
Hey ALL. I was able to finally fix my f30 error issue on my Elitebook 840 g5. Also, I was able to receive the file from HP for installation of 2023 secure boot certificates on EOSL devices. I tried running it a few times but couldn't get the certificates to enroll. I did the prerequisites before attempting, Enable 2023 MS Secure Boot keys, disabled Bitlocker. Has anyone used this file successfully from HP? Am I missing something??
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
You should mention there's a long running thread:
https://h30434.www3.hp.com/t5/Busin...ook-840-G5/m-p/9712986/highlight/true#M202121

The typical reasons for a failed KEK cert append include:
1. Wrong version of the signed KEK cert. This is less likely because the HP update script performed 3 different checks (BIOS = SBKPF, PC is a commercial model, and detected a 2013 or 2017 HP PK).

2. You have probable data corruption in the UEFI NVRAM.

HP support needs to involved HP engineering, or your laptop needs to be serviced by HP (presumably to reset/replace the BIOS).
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
GREETINGS. I know I've posted this question before. It's more important now than then. Can I get a clear, concise method to install the 2923 secure boot certificates on an HP Elitebook 840 G5? I acquired the HP package for EOSL device (Elitebook 840 G5) from HP Support. With the help of a knowledgeable contributor on HP Community, after numerous attempts, I have been unable to install the certificates on this laptop.
This is an excerpt from the last communication the contributor and I had:
EliteBook 840 is:
Model: EliteBook 840 G5
Baseboard: 83B2
BIOS: Q78 Ver. 01.31.00
Model: EliteBook 840 G5

Windows has repeatedly recorded TPM-WMI Event 1802 with SkipReason KI_7, specifically identifying the 2023 Secure Boot DB/KEK updates as being blocked by a, quote: "known firmware issue".
We subsequently confirmed that the 2023 certificates were not present in the actual firmware database.
Then we used the HP-provided enrollment package, and the HP script itself reported:
ERROR: Failed to enroll Windows UEFI CA 2023 in db database.
After that, Microsoft's Secure Boot servicing mechanism was also unable to complete the process and remained at: AvailableUpdates = 16640 (0x4100) with Event 1797 reporting that Windows UEFI CA 2023 is not present in DB.

I've recently reached out to HP Support to see if there may be an updated package for this laptop. I received this response from a Moderator:

10-01-2026 07:55 AM

Hi @NonSequitur777 , thank you for your input.

@jeobsplyr , What @NonSequitur777 mentioned is correct.

I received the same confirmation from the support team: the HP EliteBook 840 G5 reached its End of Service (EOS) on June 30, 2025, and the assigned SE PM is no longer with HP.

Product Line: Premium Notebooks
End of Production: April 15, 2020
End of OS Service: April 30, 2023
End of Service: June 30, 2025



The product has reached the end of its support lifecycle. Therefore, no further support is available.

Thanks for your patience and understanding.

Nal_NR-

With this latest information, I'm searching for a clear/concise method to install these certificates. Understand, I don't profess to be highly literate in navigating technical solutions to pc/laptop issues, but, given proper guidance, I'm willing to attempt a solution. If no other method/procedure is possible/available, so be it. I did notice a couple of members had success installing the certificates on HP Elitebook 840 G5. If any of those members could weigh in on this post, I'd greatly appreciate it. PEACE!!
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
Do you have HP Sure Start in your HP EliteBook 840 G5 notebook PC ?

My EliteBook 840 G5 notebook has HP Sure Start and I was able to install Microsoft CA 2023 certificates with ease. I have the same BIOS update as you.

Waiting your answer.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro build 26200.8524Intel i7-4790Teams DDR3-1600 4x4 GBMSI Nvidia GeForce GTX 1050Ti
    OS
    Windows 11 Pro build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-4790
    Motherboard
    Asus H97 Pro Gamer with add-on TPM1.2 module
    Memory
    Teams DDR3-1600 4x4 GB
    Graphics Card(s)
    MSI Nvidia GeForce GTX 1050Ti
    Sound Card
    Realtek ALC1150
    Monitor(s) Displays
    Dell P2425D
    Screen Resolution
    2560 by 1440 pixels
    Hard Drives
    Corsair NVMe M.2 Core XT 1000 GB (Windows 11 v.25H2); Samsung SATA Evo 870 500 GB (Windows 11 v.25H2);
    PSU
    Corsair HX850
    Case
    Gigabyte Solo 210
    Cooling
    Zalman CNPS7X Tower
    Keyboard
    Microsoft AIO Wireless (includes touchpad)
    Mouse
    HP S1000 Plus Wireless
    Internet Speed
    500 Mb fiber optic
    Browser
    Chrome; MS Edge
    Antivirus
    Windows Defender
  • At a glance

    MacOS 12 MontereyIntel Core i58 GBIntel integrated
    Operating System
    MacOS 12 Monterey
    Computer type
    Laptop
    Manufacturer/Model
    Apple Macbook Air
    CPU
    Intel Core i5
    Memory
    8 GB
    Graphics card(s)
    Intel integrated
    Screen Resolution
    1440 by 900 pixels
    Hard Drives
    128 GB
    Keyboard
    Built-in
    Mouse
    Microsoft Wireless
    Internet Speed
    802.11 ac
    Browser
    Chrome; Safari
    Antivirus
    N/A
Yes, my laptop has HP Sure Start. BIOS is: HPQ78, version 01.31.00 updated 3/10/25.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
I have written a manual procedure for people who could not update their PCs to Microsoft UEFI CA 2023 certificates.


When I updated my HP EliteBook 840 G5 notebook in April 2026, I used a different approach as delineated in the following HP forum. Please note the method mentioned in this forum does not take into account HP Sure Start technology. So additional steps are necessary to be taken. My procedure includes these necessary steps.


In above HP forum, my nickname is ForumGuy. If you follow the method in HP forum, please read all of my posts in seven pages.

For some steps in the procedures, you may need administrator BIOS password.

If anything comes to your mind, please do not hesitate to ask. Due to possible time zone differences, there may be delays in my answers.

Please also remember that whatever you do, you do it at your own risk.

Hope this helps.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro build 26200.8524Intel i7-4790Teams DDR3-1600 4x4 GBMSI Nvidia GeForce GTX 1050Ti
    OS
    Windows 11 Pro build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-4790
    Motherboard
    Asus H97 Pro Gamer with add-on TPM1.2 module
    Memory
    Teams DDR3-1600 4x4 GB
    Graphics Card(s)
    MSI Nvidia GeForce GTX 1050Ti
    Sound Card
    Realtek ALC1150
    Monitor(s) Displays
    Dell P2425D
    Screen Resolution
    2560 by 1440 pixels
    Hard Drives
    Corsair NVMe M.2 Core XT 1000 GB (Windows 11 v.25H2); Samsung SATA Evo 870 500 GB (Windows 11 v.25H2);
    PSU
    Corsair HX850
    Case
    Gigabyte Solo 210
    Cooling
    Zalman CNPS7X Tower
    Keyboard
    Microsoft AIO Wireless (includes touchpad)
    Mouse
    HP S1000 Plus Wireless
    Internet Speed
    500 Mb fiber optic
    Browser
    Chrome; MS Edge
    Antivirus
    Windows Defender
  • At a glance

    MacOS 12 MontereyIntel Core i58 GBIntel integrated
    Operating System
    MacOS 12 Monterey
    Computer type
    Laptop
    Manufacturer/Model
    Apple Macbook Air
    CPU
    Intel Core i5
    Memory
    8 GB
    Graphics card(s)
    Intel integrated
    Screen Resolution
    1440 by 900 pixels
    Hard Drives
    128 GB
    Keyboard
    Built-in
    Mouse
    Microsoft Wireless
    Internet Speed
    802.11 ac
    Browser
    Chrome; Safari
    Antivirus
    N/A
Can you give the exact page(s) in which you describe your method? From what source does the certificates come from? Trying to get a handle on what you describe as your method to install the certificates. Kind of hard for me to disseminate through the different responses.
 

My Computer My Computer

At a glance

Windows 11Intel Core i5 8350UDDR4 32GBIntel UHD Graphics 620
OS
Windows 11
Computer type
Laptop
Manufacturer/Model
HP Elitebook 840 G5
CPU
Intel Core i5 8350U
Motherboard
HP 83B2
Memory
DDR4 32GB
Graphics Card(s)
Intel UHD Graphics 620
Hard Drives
1
Can you give the exact page(s) in which you describe your method?
Hi.

You must read all responses in HP forum. This is important. You must get a good understanding of certificate installation. I cannot do the reading for you. I have read a lot of articles over the web, especially @garlin 's posts, replies, etc. Otherwise, you may do something bad unintentionally. There are only seven pages to read.
From what source does the certificates come from?
Certificates source is github website. Github website is owned by Microsoft. From this I understand that you haven't even opened the web sites.
Trying to get a handle on what you describe as your method to install the certificates. Kind of hard for me to disseminate through the different responses.
My method is for HP notebooks with HP Sure Start Tech. Nothing more.

As I told you before, I used the method posted in HP forum. You may also follow that method. The only thing is, that method does not take HP Sure Start technology into account. The certificates of that method also come from Github website.

Hope this helps.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro build 26200.8524Intel i7-4790Teams DDR3-1600 4x4 GBMSI Nvidia GeForce GTX 1050Ti
    OS
    Windows 11 Pro build 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-4790
    Motherboard
    Asus H97 Pro Gamer with add-on TPM1.2 module
    Memory
    Teams DDR3-1600 4x4 GB
    Graphics Card(s)
    MSI Nvidia GeForce GTX 1050Ti
    Sound Card
    Realtek ALC1150
    Monitor(s) Displays
    Dell P2425D
    Screen Resolution
    2560 by 1440 pixels
    Hard Drives
    Corsair NVMe M.2 Core XT 1000 GB (Windows 11 v.25H2); Samsung SATA Evo 870 500 GB (Windows 11 v.25H2);
    PSU
    Corsair HX850
    Case
    Gigabyte Solo 210
    Cooling
    Zalman CNPS7X Tower
    Keyboard
    Microsoft AIO Wireless (includes touchpad)
    Mouse
    HP S1000 Plus Wireless
    Internet Speed
    500 Mb fiber optic
    Browser
    Chrome; MS Edge
    Antivirus
    Windows Defender
  • At a glance

    MacOS 12 MontereyIntel Core i58 GBIntel integrated
    Operating System
    MacOS 12 Monterey
    Computer type
    Laptop
    Manufacturer/Model
    Apple Macbook Air
    CPU
    Intel Core i5
    Memory
    8 GB
    Graphics card(s)
    Intel integrated
    Screen Resolution
    1440 by 900 pixels
    Hard Drives
    128 GB
    Keyboard
    Built-in
    Mouse
    Microsoft Wireless
    Internet Speed
    802.11 ac
    Browser
    Chrome; Safari
    Antivirus
    N/A

Latest Support Threads

Back
Top Bottom