• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
OMEN 30L Desktop PC GT13-1000a (207P7AV)

I have an HP OMEN 30L GT13-1000a, Product Number 399T3AA#ABA, with motherboard/SSID 8876 and BIOS F.24 dated 10/8/2025.

Secure Boot worked previously. After BIOS F.24, enabling Secure Boot causes the system to stop before Windows loads and display: "Secure Boot Violation - Invalid signature detected. Check Secure Boot Policy in Setup."

My system is Windows 11 Home 25H2, UEFI mode, GPT, with TPM 2.0 enabled and functioning. The Platform Key is enrolled, and the Secure Boot databases PK, KEK, db, and dbx are present.

I also verified that the Windows Boot Manager file bootmgfw.efi has a valid signature. Windows boots normally when Secure Boot is disabled.

I have already tried restoring/loading the HP default Secure Boot keys and checking the boot order. I also previously encountered "Boot Device Not Found" and Secure Boot violation messages when changing the BIOS settings, so I do not want to make further BIOS changes without confirmed HP guidance.

The game I am trying to play "Call of Duty" currently reports that Secure Boot is not enabled and therefore does not meet its security requirements.

HP Support Community has another report involving the same OMEN 30L GT13-1xxx, motherboard 8876, BIOS F.24, and the same "Invalid Signature Detected" error.

Could you please investigate whether BIOS F.24 has a Secure Boot firmware or key issue on this platform and provide the official HP recovery procedure or firmware fix? I do not want to downgrade the BIOS or reinstall Windows unless HP confirms that it is necessary.

3 REPLIES 3
HP Recommended

Your GT13-1000a is in this list, it is also discussed here, but fortunately, it is not yet in this list.

 

I have asked HP Admin if your GT13-1000a  is going to be updated, but you might consider GeForce Now in the meantime.  In regards to that GeForce Now you might want to read this post by our upgrade expert @NonSequitur777 

 

On a side note, I noticed that you currently have cloud restore capability.

You should get a copy of it before it is removed.  I recall HP removes it about 5 years after warranty expires.


Thank you for using HP products and posting to the community.
I am a community volunteer and do not work for HP. If you find
this post useful click the Yes button. If I helped solve your
problem please mark this as a solution so others can find it
HP Recommended

Thank you for checking on this. I found the HP documentation about AMD TPM attestation failures, and I noticed that the OMEN Desktop PC 30L GT13-0xxxa is listed among the legacy platforms that will not receive the TPM 3.92.5.5 BIOS update.

My system is the OMEN 30L GT13-1000a (399T3AA#ABA), motherboard 8876, BIOS F.24. I understand that this may explain the TPM attestation issue with Call of Duty, but my main problem right now appears to be separate.

My TPM 2.0 is present and functioning, but when I enable Secure Boot, the PC stops before Windows loads with “Secure Boot Violation - Invalid signature detected. Check Secure Boot Policy in Setup.” Secure Boot worked previously, and this started after BIOS F.24.

When Secure Boot is disabled, Windows boots normally. I have also verified UEFI/GPT, Platform Key enrollment, the Secure Boot databases, and that bootmgfw.efi has a valid signature.

Because I have already experienced Boot Device Not Found and TPM/security-data prompts while troubleshooting, I don’t want to clear the TPM or make any more BIOS changes without confirmed HP guidance.

Could you please confirm whether the GT13-1000a/8876 platform is expected to receive a Secure Boot certificate or firmware update, and whether the Secure Boot invalid-signature issue is related to the AMD TPM attestation issue or is a separate F.24 firmware problem?

Thank you for looking into this.

HP Recommended

@BeemerBiker,

 

Yes, your feedback is right on target.

 

@Kmixxed,

 

May I say that you have actually done a very good job of narrowing this down, and I would not recommend reinstalling Windows or continuing to experiment with the Secure Boot keys at this point.

 

There are several important clues here.

 

First, your OMEN 30L GT13-1000a with motherboard/ROM Family SSID 8876 is not one of the platforms HP has identified as receiving no further BIOS updates for the TPM/attestation issue. That's encouraging, but it is important not to conflate the two issues. TPM attestation and Secure Boot are related security technologies, but they are not the same problem.

 

More importantly, there is now considerable evidence that SSID 8876 has a Secure Boot/SBAT firmware issue with BIOS F.24.

 

HP itself has acknowledged in another SSID 8876 discussion that F.24 (October 2025) is the current BIOS for this motherboard, and that HP is working on updated firmware involving the newer Microsoft Secure Boot/SBAT requirements. HP specifically stated that the current F.24 firmware does not yet support the updated Microsoft SBAT 2023 certificates and that a compatible BIOS is expected through HP's normal update channels.

 

There is also another very relevant SSID 8876 report in the HP Community in which an OMEN 30L owner describes essentially the same situation: AMI F.24, Secure Boot unable to remain enabled, TPM working, UEFI/GPT confirmed, and the same Secure Boot problems.

 

And there is now yet another recent SSID 8876 report from an OMEN 30L owner who says that after F.24, Secure Boot became unusable and Call of Duty subsequently reported that Secure Boot was disabled.

 

In your particular case, the error is especially significant.

 

You are getting:

 

Secure Boot Violation

Invalid signature detected. Check Secure Boot Policy in Setup.

 

whilst Windows Boot Manager itself has been verified as properly signed, and you have confirmed:

 

  • UEFI boot
  • GPT
  • TPM 2.0 functioning
  • Platform Key enrolled
  • PK/KEK/db/dbx populated
  • Windows Boot Manager present and correctly configured
  • HP factory Secure Boot keys loaded
  • no custom bootloader
  • Windows boots normally with Secure Boot disabled

 

That makes a corrupt Windows installation or an improperly configured GPT/UEFI installation considerably less likely.

 

The fact that the firmware itself rejects the boot chain only when Secure Boot is enabled points much more toward the firmware's Secure Boot policy/certificate/SBAT handling.

 

In other words, I would not jump to bcdboot, a clean Windows installation, or replacing the motherboard. Those procedures address the Windows boot environment; they do not correct a defective or obsolete Secure Boot implementation in the motherboard firmware.

 

I would also leave F.24 installed.

 

I would not recommend downgrading F.24 on your own.

 

There are reports of older BIOS versions being offered on HP's web site for this platform, which makes the situation particularly confusing. But HP has specifically identified F.24 Rev. A as the current BIOS for ROM Family SSID 8876, with an October 19, 2025 release date.

 

So, I would not deliberately flash an older ROM merely as an experiment.

 

What I would do now:

 

For the moment:

 

1. Leave Secure Boot disabled so that Windows remains bootable.

2. Don't clear the Secure Boot keys again. You've already established that the keys are present and that the Platform Key is enrolled.

3. Don't reinstall Windows. Nothing you've described establishes that Windows is the cause.

4. Don't downgrade F.24 without specific HP instructions.

5. Keep Windows fully updated and monitor HP's support page/HP Support Assistant for a newer BIOS for ROM Family SSID 8876.

The key thing we need from HP is a newer 8876 BIOS containing the appropriate Secure Boot/SBAT/certificate changes, rather than another Windows-side repair.

 

HP has stated that when the appropriate firmware is released, it will be distributed through HP's support site, HP Support Assistant, or Windows Update as system firmware.

 

So, unfortunately, I think your instinct not to make further BIOS changes without confirmed HP guidance is the right one.

 

And I would definitely mention the exact combination of OMEN 30L GT13-1000a / 399T3AA#ABA / SSID 8876 / F.24 / Secure Boot Violation – Invalid Signature Detected when contacting HP. There is now enough evidence from other SSID 8876 systems that this should be investigated as a platform firmware issue, rather than treated as an ordinary Windows Secure Boot configuration problem.

 

One final point: the fact that Call of Duty is complaining about Secure Boot does not mean Call of Duty itself is causing the failure. Your PC is actually failing before Windows loads when the firmware's Secure Boot enforcement is enabled. That makes this fundamentally a UEFI firmware/boot-chain validation problem, not necessarily a Call of Duty problem.

 

Bottomline is this: I would therefore wait for HP's firmware fix rather than risk turning a currently bootable computer into an unbootable one.

 

Kind Regards,

 

NonSequitur777


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->