• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
OMEN by HP 45L Gaming Desktop PC GT22-0000i (393C6AV)
Microsoft Windows 11

Secure Boot Violation – Invalid signature detected. Check Secure Boot Policy in Setup  with a GT22-0139 Omen Gaming 45 . Happened a few days ago  ,  and since it does not access the secure boot , it does not see the hard drive ( next screen is F0 erroR for the hard disk , which is working )

 

Tested all , No hardware issues , replaced the CMOS battery ,  but the only way to start windows is to disable secure boot ..The logs in tests show the date is 2021 , but there’s nowhere to change the date in the Omen setup utility .

In the BIOS menu , my only option was to clear the Keys but not to upload  or restore factory keys . I also updated to the latest BIOS , no change . How or where to get this restore keys function activated ?  is there another menu other than the Omen setup that can be used ?

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions
HP Recommended

Greetings @ZigZagMan 

 

Try the solution at this HP Forum Thread.

 

Some folks are very happy after following the detailed steps described at the above Forum thread.

 

Regards

View solution in original post

2 REPLIES 2
HP Recommended

Greetings @ZigZagMan 

 

Try the solution at this HP Forum Thread.

 

Some folks are very happy after following the detailed steps described at the above Forum thread.

 

Regards

HP Recommended

Thank you  , 

Tested the suggested steps with Grok and it gave me the ok . 

My steps : 

Recommendation for your HP OMEN GT22-XXXX

This method is currently one of the most reliable ways to fix the Secure Boot violation related to the 2023 certificates (especially after installing updates like KB5074110 or after resetting Secure Boot keys).

 

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

 

My advice :

Please do an image backup before Hand and test your backup software ( mine is Acronis)  with USB recovery to see if you can the recovery mode  , in case nothing else  works  and you need to reimage . I know I should not have to say it 

 

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

Here’s the clean, step-by-step version tailored for your HP OMEN GT22-XXXX:

Prepare the Recovery USB

  1. Boot into Windows with Secure Boot disabled.
  2. Insert a USB flash drive (8 GB or larger). ( I only used an old 500 MB USB)
  3. Format it as FAT32 (important).
  4. Create this exact folder structure on the USB:
  5. EFI

└── BOOT

  1. Copy this file:

C:\Windows\Boot\EFI\SecureBootRecovery.efi

  1. Paste it into the EFI\BOOT folder on the USB.
  2. Rename the copied file from SecureBootRecovery.efi to:

BOOTX64.EFI

 

Run the Recovery

  1. Restart the computer.
  2. Immediately start pressing the Esc key repeatedly.
  3. When the HP Startup Menu appears, press F9 (Boot Device Options).
  4. Select your USB drive (it should say something like “UEFI: USB…”).
  5. The screen should go black and show a message similar to:

“Updating the Secure Boot Certificate database with the Microsoft UEFI 2023 certificate”

  1. Wait until it finishes and the computer restarts automatically.

Final Step  ( Remove the USB or the script will run again )

  1. Enter BIOS again (Esc → F10).
  2. Go to the Security or Secure Boot section.
  3. Make sure Secure Boot is set to Enabled.
  4. Change the boot order back to what it was  ( not USB first)
  5. Save changes and exit (F10 → Yes).

After this, Windows should boot normally with Secure Boot enabled.

Would you like me to also give you the optional verification command to check if the 2023 certificate was successfully added?

 

Here’s the optional verification command:

Check if the 2023 Certificate is present

  1. Boot into Windows.
  2. Open PowerShell as Administrator.
  3. Run this command:

[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI -Name db).Bytes) -match "Windows UEFI CA 2023"

How to interpret the result:

  • True → The Windows UEFI CA 2023 certificate has been successfully added.
  • False → The 2023 certificate is not present (you still have the old certificates or the recovery failed).ZigZagMan_1-1789679238836.png

     

    You can aslo check MSINFO and it should show  Secure Boot on 

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->