• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
Microsoft Windows 10 (64-bit)

Hi Guys,
I need some help here as my HP Z420 Base Model Workstation recently was prompted that it failed to perform a Microsoft Windows Update on Boot Secure Certificate.  I have noticed a slow boot up of my desktop and there are times when the desktop trying to recover from the "Sleep" mode, it was not able to recover quickly or successfully. I have tried to look for a HP BIOS update, but I noticed that the update there is not the latest version.  Nevertheless, I too downloaded it and installed it but it does not help to resolve the Boot Secure Certificate issue. 

Can anybody out there help me to get a fix on how to resolve this Boot Secure Certificate issue for my desktop (HP Z420 Base Model Workstation).  Thank you. 

1 ACCEPTED SOLUTION

Accepted Solutions
HP Recommended

Hi @Horatius,

Thank you for getting back to me. I understand why you are considering disabling Secure Boot or enabling Legacy Support, given that the HP Z420 is not listed in HP's current supported-platform list for the new Secure Boot certificates.
 

I have rechecked HP's current documentation, and I would not recommend disabling Secure Boot or enabling Legacy Support as a workaround for the new Secure Boot certificate issue.
 

The reason is that neither setting installs or updates the new Microsoft 2023 Secure Boot certificates. They only change how the system handles Secure Boot and boot compatibility.
 

More importantly, the HP Z420 is an older workstation and is not included in HP's current supported-platform list for the 2023 Secure Boot certificate transition. HP's current guidance covers supported commercial systems released in 2019 and later, along with selected 2018 systems. Older EOSL systems do not receive the BIOS update associated with this certificate transition. 
 

Therefore, I would recommend keeping Secure Boot enabled if the system is currently booting correctly rather than changing the BIOS configuration simply to work around the missing certificate update.
 

The Z420's previous BIOS 3.91 Secure Boot update should not be confused with the current 2023 certificate update; HP's documentation for that older update does list the Z420, but it is not the current certificate-transition solution. 

If you are currently receiving a specific Secure Boot, Windows Boot Manager, or certificate-related error on the Z420, share the exact error message or a photograph of the screen. We can then determine what options are actually available for that particular situation rather than recommending a BIOS change that will not address the underlying certificate limitation.
 

I would not disable Secure Boot or switch to Legacy Support solely because the new certificate is unavailable for this model.
 

That is the version I would use. It avoids claiming that the Z420 is supported when it isn't listed in the current HP certificate program, and it correctly separates the old Z420 Secure Boot BIOS update from the 2023 Secure Boot certificate transition. HP itself also recommends against disabling Secure Boot as a way of avoiding the certificate transition.

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

View solution in original post

6 REPLIES 6
HP Recommended

Hi @Horatius,

Welcome to the HP Support Community.
 

Thank you for providing the details of your HP Z420 Base Model Workstation.
 

The message you're seeing regarding the Microsoft Secure Boot Certificate is related to Microsoft's Secure Boot certificate update. HP has released BIOS updates for select commercial platforms to support this update.
 

For reference, please see the HP document below: HP Business PCs - Prepare for new Windows Secure Boot certificates | HP® Support
 

After reviewing your model, the HP Z420 Workstation is not included in the list of supported platforms for this Secure Boot certificate update. Additionally, the Z420 is an obsolete/end-of-support product, and there are no newer BIOS updates or firmware fixes available beyond those already published for this model.
 

Since you've already updated the BIOS to the latest version available for the Z420, there are no additional HP BIOS updates that can be applied to address this specific Secure Boot certificate notification.
 

Regarding the slow boot and resume from Sleep, these symptoms are not necessarily caused by the Secure Boot certificate message and may instead be related to Windows, storage health, drivers, or the age of the hardware.
 

If the Secure Boot certificate update is a requirement for your environment, you may need to consider migrating to a newer HP platform that is listed in the HP support document above.
 

I hope this clarifies the situation. Please let us know if you have any additional questions regarding your Z420, and we'll be happy to assist where HP support is available.

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

HP Recommended

Hi VikramTheGreat,

Thank you for your reply.  Since you said that my HP Z420 Base Model Workstation running on Windows 10 Professional, is an obsolete/end-of-support product, does it means that there is totally no hope of rectifying this Secure Boot Certificate update issue that is found in my computer; the notification of the exclamation mark (!) that is present in my Windows Security?  I really have no intention of changing my computer now, be it due to budget constraint or my computer is still able to serve me very well before this Secure Boot Certificate issue.

 

As for the slow boot and resume from the Sleep mode, these symptoms, I do not have it in the past.  I only have it now after this Secure Boot Certificate issue.  I still have quite a substantial amount of hard disk memory for my computer (241GB ouf of 465GB for Drive C and 403GB out of 458GB for Drive D) with an installed RAM of 32GB.  So, I don't think the slow boot and resume from the Sleep mode is due to the bad storage health.

 

I really hope there is a solution to it and you can really help me out with it.  I really dislike seeing the notification of the exclamation mark (!) in the Windows Security or compromise of the performance of my computer due to Secure Boot Certificate.

 

Hope to hear from you soom.  Thank you. 

 

HP Recommended

Hi @Horatius,

Thank you for your detailed update, and I completely understand your concerns. I can appreciate why you'd want to resolve the Secure Boot Certificate notification, especially since your HP Z420 Workstation has been serving you well and you're not planning to replace it at this time.
 

To clarify, the fact that the HP Z420 is an end-of-support product does not necessarily mean there is something wrong with your workstation or that it can no longer be used. It simply means that HP has reached the end of the planned support lifecycle for this model. As a result, driver, BIOS, firmware, and security updates are only available if they were released during the product's supported lifecycle.
 

I also understand your observation that the slower boot time and resume from Sleep only began after the Secure Boot Certificate notification appeared. Since your system has sufficient available storage and 32 GB of RAM, those resources are unlikely to be the cause of the behavior you're seeing.
 

At this point, HP's support options for this model are limited to the software, BIOS, and firmware versions that were released while the product was supported. If HP releases any additional updates applicable to this model in the future, it would be made available through the HP Support website. However, at this time, there are no newer HP updates available beyond those already published for the HP Z420.
 

I understand this may not be the answer you were hoping for, and I'm sorry we don't have additional HP-released updates to offer for this particular model. Your workstation can certainly continue to be used if it is otherwise functioning normally, but because it is outside its support lifecycle, our ability to provide new fixes or patches for newly identified issues is unfortunately limited.
 

We truly appreciate your patience and the time you've taken to work through the troubleshooting with us. If you notice any new symptoms or have additional questions, please let us know. We'll always do our best to help with the support resources available for your HP Z420 Workstation.

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

HP Recommended

Hi Vikram,

Thank you for getting back to me.  I really appreciate that!  Since there is no solution so far to the issue of the Secure Boot Certificate for my computer, would it be advisable for me to turn off the Secure Boot or turn on the Legacy Support on my computer's BIOS?

 

Hope to hear from you again.  Thank you.

HP Recommended

Hi @Horatius,

Thank you for getting back to me. I understand why you are considering disabling Secure Boot or enabling Legacy Support, given that the HP Z420 is not listed in HP's current supported-platform list for the new Secure Boot certificates.
 

I have rechecked HP's current documentation, and I would not recommend disabling Secure Boot or enabling Legacy Support as a workaround for the new Secure Boot certificate issue.
 

The reason is that neither setting installs or updates the new Microsoft 2023 Secure Boot certificates. They only change how the system handles Secure Boot and boot compatibility.
 

More importantly, the HP Z420 is an older workstation and is not included in HP's current supported-platform list for the 2023 Secure Boot certificate transition. HP's current guidance covers supported commercial systems released in 2019 and later, along with selected 2018 systems. Older EOSL systems do not receive the BIOS update associated with this certificate transition. 
 

Therefore, I would recommend keeping Secure Boot enabled if the system is currently booting correctly rather than changing the BIOS configuration simply to work around the missing certificate update.
 

The Z420's previous BIOS 3.91 Secure Boot update should not be confused with the current 2023 certificate update; HP's documentation for that older update does list the Z420, but it is not the current certificate-transition solution. 

If you are currently receiving a specific Secure Boot, Windows Boot Manager, or certificate-related error on the Z420, share the exact error message or a photograph of the screen. We can then determine what options are actually available for that particular situation rather than recommending a BIOS change that will not address the underlying certificate limitation.
 

I would not disable Secure Boot or switch to Legacy Support solely because the new certificate is unavailable for this model.
 

That is the version I would use. It avoids claiming that the Z420 is supported when it isn't listed in the current HP certificate program, and it correctly separates the old Z420 Secure Boot BIOS update from the 2023 Secure Boot certificate transition. HP itself also recommends against disabling Secure Boot as a way of avoiding the certificate transition.

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

HP Recommended

Hi VikramTheGreat,

Thank you for your prompt reply.  As per your advice, I will not disable the Secure Boot or enable the Legacy Support in the BIOS as a workaround for the new Secure Boot Certificate issue since doing so will not resolve or address the issue but it may even pose as a security threats to the existing one.

 

I can only hope that Microsoft will provide a solution or updates to those who are excluded like me, after all if we are not protected and expose to threats, eventually everybody will not be spared since we are all interconnected in the Web.

 

Lastly, thank you for the help rendered all this while and I will have to call it a case closed even though there is no solution to it.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->