• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended

Title: Network BIOS Update – “The protocol defined in the URL is not supported” – Please restore HTTP support

Hi HP,

I’m running into a recurring issue with Network BIOS Update across a wide range of HP EliteBook generations, from approximately EliteBook G2 through G10.

When attempting to use the BIOS network update functionality, the systems report:

NETWORK BIOS UPDATE – The protocol defined in the URL is not supported

The configured BIOS update URL uses HTTP, which has historically worked with HP BIOS network update functionality. On these systems, however, HTTP appears to no longer be accepted/supported.

Could HP please investigate this and, ideally, restore HTTP support for Network BIOS Update?

In managed environments, being able to point the BIOS directly at an internal HTTP firmware repository is extremely useful. Requiring HTTPS can also introduce additional problems with certificates, TLS versions, certificate authorities, and older BIOS implementations.

I’m seeing this across multiple EliteBook generations, so this does not appear to be limited to one specific model.

It would be great if an HP employee could clarify:

  • Is HTTP support intentionally being removed from Network BIOS Update?

  • Which EliteBook generations/BIOS versions are affected?

  • Is there a BIOS setting or policy that can re-enable HTTP?

  • If HTTP has been removed, could HP consider restoring support for trusted internal network environments?

Please bring HTTP support back for Network BIOS Update. It is a very useful feature for centrally managing large numbers of HP systems.

Thank you!

3 REPLIES 3
HP Recommended

Hi @tuxcrafter 

 

Welcome to the HP Support Community.

 

Thank you for posting your query.

 

HTTP support has been removed from the HP Network BIOS Update feature in recent firmware releases across commercial platforms like EliteBooks.

HP has deprecated legacy protocols and proxy options (such as unencrypted HTTP, FTP, and libcurl-based proxy configuration settings) to modernise firmware security and strictly enforce HTTPS. I would request you to please share the error message displayed on the screen.

 

Is HTTP support intentionally being removed?
Yes. HP has systematically transitioned Network BIOS Update functionality to strictly require HTTPS to align with modern corporate security baselines.

 

Which EliteBook generations/BIOS versions are affected?
This change impacts a broad scope of enterprise devices (ranging across older generations like G7 up to modern G10/G11 systems) that have been updated with recent firmware releases.

 

Is there a BIOS setting or policy to re-enable HTTP?
No. There is no toggle or policy within the F10 BIOS Setup utility to force the older, unencrypted HTTP protocol. Legacy transport options like "Force HTTP no-cache" have been fully deprecated in modern layouts. 

 

Will HP consider restoring HTTP for trusted networks?
Because this is an architectural security hardening decision designed to prevent unauthorized firmware manipulation at the pre-boot level, HP is highly unlikely to restore unencrypted HTTP support.

 

Perform a BIOS recovery Via USB once and check as this has helped other users to resolve the issue.

 

I hope this helps.

 

Take care and have an amazing day!

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

HP Recommended

Dear HP Support,

Thank you very much for your reply.

However, I believe this change is effectively breaking an important BIOS functionality on a large number of HP laptops, rather than improving security.

The BIOS firmware update mechanism previously allowed firmware to be retrieved over HTTP. Removing HTTP support means that existing custom BIOS update URLs and internal firmware repositories can no longer be used, because the BIOS does not provide an HTTPS/TLS stack and there is no option to configure a custom HTTPS endpoint.

This also creates a significant problem for organisations that maintain their own firmware repositories. They can no longer simply host the required HP firmware files internally and have the BIOS retrieve them directly.

I understand the security rationale behind HTTPS, particularly its protection against network-level modification of files and authentication of the server. However, I don't believe that removing HTTP is an appropriate substitute for cryptographic verification of firmware.

For a BIOS update mechanism, the most important security property should be that the firmware itself is cryptographically authenticated. If HP firmware packages are digitally signed and the BIOS verifies those signatures before applying an update, then the authenticity and integrity of the firmware can be enforced independently of the transport protocol.

HTTPS protects the transport channel; it does not replace firmware-level signature verification. Conversely, organisations that require stronger control over the update process can operate their own internal repository, verify HP's signatures and checksums, and control exactly which firmware versions are made available to their endpoints.

Removing HTTP therefore has the unfortunate side effect of reducing functionality for legitimate enterprise and managed-device use cases, without necessarily providing a corresponding improvement in the fundamental security of the firmware update process.

There is also another practical issue: HP's firmware repositories are no longer easily browsable or monitorable because directory listings/statistics appear to have been disabled. This makes it considerably harder for administrators to monitor repositories for newly released firmware and maintain internal mirrors.

Would HP please consider restoring HTTP support for the BIOS firmware update functionality, at least for custom/internal repositories?

I would also strongly encourage HP to consider maintaining the security boundary at the firmware-signing level rather than enforcing HTTPS as the only possible transport mechanism. Organisations should be able to choose their own secure delivery architecture while the BIOS independently verifies that the firmware is authentic and has not been modified.

It may also be useful for HP to examine the HTTP endpoints that were previously used for BIOS updates and review the volume of requests still being made to them. I suspect there are still a substantial number of HP systems attempting to retrieve firmware over these endpoints, which would give HP a good indication of how many customers are affected by this change.

Thank you for considering this request. Restoring HTTP support would significantly improve compatibility for existing systems and enterprise firmware-management workflows.

HP Recommended

Hi @tuxcrafter 

 

Thank you for responding.

 

I would request you to please check whether the Custom URL option is available under Network BIOS Update on the affected system?

If the option is available, we would like to request that you test the feature using an internal HTTP URL that does not redirect to HTTPS. Some administrators have reported that this may serve as a workaround for the error:

 

Additionally, please note that HTTPS provides an extra layer of security by encrypting the connection and authenticating the server. This helps protect BIOS update traffic from being intercepted or modified while it is being transferred across the network. While the BIOS itself verifies the authenticity and integrity of the firmware package before installation, that validation does not secure the network connection in the same way that HTTPS does. For this reason, HTTPS offers additional protection compared to HTTP.

As a test, please configure the Custom URL option to point to a suitable internal HTTP endpoint and verify whether the Network BIOS Update is able to successfully retrieve the BIOS update without being redirected to HTTPS.

Please let us know the outcome of the test, along with any error messages or screenshots, so we can further assist you.

 

Have a good day.

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->