• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended

I am running into an issue with secure boot on my Omen 25gl gt12-1000A with secure boot on BIOS version F.24 Rev.A.

 

I'm getting a secure boot violation: invalid signature detected. Windows 11 installed UEFI mode. Microsoft bootmgfw.efi signature is valid. Secure boot keys are enrolled. BIOS reflashed and TPM reset. Secure boot still rejects boot.

 

To expand on the checklist I have ran through: I have verified UEFI mode, Verified windows boot manager path, rebuilt EFI boot files, Verified SFC/DISM health, Verified secure boot keys exist (pk/kek/db/dbx), verified Microsoft boot loader signature is valid, reset TPM after BIOS changes, Reflashed the BIOS and removed USB variables... Still get secure boot violation message as soon as secure boot is selected "on". However can still load into windows as long as secure boot is off.

 

I also did a double check running "mountvol S:  /S" then "dir S:  \EFI" and found as expected only Microsoft, Boot and HP are present no wacky 3rd party bootloaders. 

 

At this point I am trying to determine whether this is a firmware bug in BIOS F.24 Rev.A or a hardware issue with the motherboard's secure boot implementations. 

 

Any advise would be greatly appreciated!

1 REPLY 1
HP Recommended

Hi  @JackLehman 
 
Welcome to the HP Support Community!

Thanks for reaching out!


I understand how it must be to spend so much time and encountering the "Secure Boot Violation: Invalid Signature Detected" message. I appreciate all the effort you've put into diagnosing this problem.

Could you kindly confirm the below details: 

  • Was Windows 11 preinstalled on the system, or was it upgraded/reinstalled at any point?
  • Did the issue start immediately after updating to BIOS F.24 Rev.A, or was Secure Boot functioning properly before the BIOS update?

Since you have already performed many steps, Below are a few additional checks that may help:

1. Restore Factory Secure Boot Keys

  • Disable Secure Boot.
  • Navigate to Secure Boot Key Management (if available).
  • Select Restore Factory Keys or Load HP Factory Secure Boot Keys.
  • Save changes and restart.
  • Re-enable Secure Boot and test.

2. Verify Legacy Boot Settings Please ensure:

  • Legacy Support = Disabled
  • Boot Mode = UEFI Only

We have seen a similar case discussed in the HP Community where another user encountered the same "Secure Boot Violation - Invalid Signature Detected" error.Reviewing the steps and solution in that discussion may be helpful, as it helped the user resolve the issue: Click here .

 

I hope this helps. 

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.