• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
OMEN by HP 875-1000 Obelisk Desktop PC (5MG70AV)
Microsoft Windows 11

I'm having a TPM/Secure Boot attestation problem with Fortnite/Easy Anti-Cheat.

The error says: “TPM attestation failed: unable to verify secure boot. event missing from measured bootlog.”

I have already updated my HP BIOS and confirmed that TPM 2.0 is ready for use, Secure Boot is enabled, and Windows is running in UEFI mode.

Windows Measured Boot is reporting that Secure Boot is enabled on the computer but is not being recorded correctly in the TCG measured-boot log. Windows Event Viewer also shows repeated Kernel-Boot Event ID 292 errors saying: “Failed to update the SBAT value in FW.”

I’m looking for help determining whether this is an HP firmware/Secure Boot/SBAT issue and whether there is a recommended firmware fix.

6 REPLIES 6
HP Recommended

Greetings,

 

Please provide your HP PC's BIOS version/date and Baseboard product.

 

Enter msconfig in Windows Search. Open msconfig. The product details are located in System Summary.

 

HP Support Assistant or HP System information should provide this information. Or follow instructions at this HP Site.

 

A newer BIOS version, if one is available, might correct the Secure Boot error.

 

If a BIOS update fixes the Secure Boot problem you may still encounter a TPM 2.0 version problem because your PC was released for sale circa 2018 or possibly 2021.

 

875-1000 series PCs are using four different MBs. With an Intel/AMD mix.

 

We need to ID your PC's MB.

 

Regards

HP Recommended

Hello,

Thank you. Here are the requested details:

BIOS Version/Date: AMI F.35, 12/19/2023
Baseboard Product: 84FD
Product/SKU: 4NN77AA#ABA

I have already installed the available HP BIOS update, and the system is currently running F.35.

The issue is still occurring after the BIOS update. TPM 2.0 is ready for use and reports that it is capable and ready for attestation. Secure Boot is enabled, Windows is running in UEFI mode, and PowerShell Confirm-SecureBootUEFI returns True.

However, the Windows Measured Boot JSON reports:

SecureBootEnabled: ValueFromComputer = true
SecureBootEnabled: ValueFromTcgLog = false

It also reports TcgLogFound = true and PcrsMatchTcgLog = true.

Additionally, Windows Event Viewer shows repeated Kernel-Boot Event ID 292 errors with the message:

“Failed to update the SBAT value in FW.”

Easy Anti-Cheat/Fortnite then reports:

“TPM attestation failed: unable to verify secure boot. event missing from measured bootlog.”

Could you please confirm whether BIOS F.35 for motherboard 84FD has a known Secure Boot/SBAT/measured-boot issue, and whether there is a newer or corrected BIOS/firmware version available for this specific motherboard?

Thank you.

HP Recommended

Greetings @rd146 

 

I don't work for HP. I cannot verify a BIOS version F.35 SBAT/Secure Boot problem.

 

HP Support reps participating in this Form may not be able to answer this question without consulting the folks compiling the firmware.

 

HP, as well as other PC and MB OEMs, typically limits on-going BIOS support to about four or five years, I would guess your PC may not see any future BIOS updates.

 

Your PC could also have a TPM 2.0 manufacturing version problem when playing certain games. HP has decided to not update the TPM firmware on many HP PCs released for sale subsequent to your PC's release for sale date.

 

@NonSequitur777 might have additional insight on this subject matter.

 

Regards

 

 

HP Recommended

Thank you for the clarification.

I understand that you cannot verify whether F.35 has a known SBAT/Secure Boot issue. However, I would like to clarify that the evidence I have found points to a specific Secure Boot measured-boot/firmware issue rather than simply an unsupported TPM.

My TPM reports:

  • TPM 2.0

  • TPM Ready: True

  • Ready For Attestation: True

  • Capable For Attestation: True

  • TPM firmware is not reported as vulnerable

Secure Boot is enabled in BIOS, the Platform Key is enrolled, Legacy Support is disabled, Windows is booting in UEFI mode, and PowerShell Confirm-SecureBootUEFI returns True.

However, the Windows Measured Boot JSON reports:

SecureBootEnabled:

  • ValueFromComputer: true

  • ValueFromTcgLog: false

The same log reports TcgLogFound = true and PcrsMatchTcgLog = true.

Additionally, Windows Event Viewer repeatedly reports Kernel-Boot Event ID 292:

"Failed to update the SBAT value in FW."

Easy Anti-Cheat then reports:

"TPM attestation failed: unable to verify secure boot. event missing from measured bootlog."

Could you please have someone with HP firmware knowledge determine whether this combination is a known issue with motherboard 84FD and BIOS F.35, or advise whether there is any supported HP firmware/BIOS procedure for correcting the SBAT/measured-boot issue?

I am not asking for a generic TPM/Secure Boot explanation, since both are already enabled and functioning according to Windows. I am specifically trying to determine why Secure Boot is being reported as true by Windows but false in the TCG measured-boot log.

Thank you.

HP Recommended

Greetings @rd146 

 

My pleasure.

 

I'm an independent Forum volunteer. I don't have inside contacts in this Forum or with HP.

 

I know you have a Secure Boot problem.

 

I'm saying the PC may also have a TPM version problem due to the PC's age.

 

So you could have two unsolvable issues. And it is highly probable your PC's MB will no longer receive future firmware updates.

 

Maybe a different Forum member can assist.

 

Regards

HP Recommended

@rd146,

 

I agree that your evidence points to something more specific than a normal TPM or Secure Boot configuration problem.

 

There's really not a whole lot I can add in addition to what @Bill_To already discussed with you.

 

Summarizing, you have demonstrated that:

 

  • BIOS F.35 is installed, which is the latest publicly available BIOS for motherboard 84FD.
  • TPM 2.0 is ready and capable of attestation.
  • Secure Boot is enabled, the Platform Key is enrolled, and the system is booting in UEFI mode.
  • Confirm-SecureBootUEFI returns True.
  • Windows reports TcgLogFound = true and PcrsMatchTcgLog = true.
  • Yet the measured-boot data reports SecureBootEnabled.ValueFromComputer = true whilst ValueFromTcgLog = false.
  • Kernel-Boot Event 292 repeatedly reports "Failed to update the SBAT value in FW."

 

That combination is significant.

 

Windows can see that Secure Boot is enabled, but the corresponding Secure Boot measurement is apparently not being recorded in the TCG measured-boot log in the manner expected by the attestation software. That explains why Easy Anti-Cheat can report "event missing from measured bootlog" even though Secure Boot itself is functioning.

 

The Event 292 SBAT failure provides additional evidence that the firmware is involved.

 

However, I would stop short of calling this an officially confirmed HP firmware defect. HP has not published a bulletin identifying F.35/84FD as having an SBAT or measured-boot bug.

 

Unfortunately, HP's latest public information indicates that F.35 remains the newest BIOS available for the 84FD, with no newer corrective BIOS currently offered. An HP moderator also recently confirmed that there are no newer BIOS updates available for this model.

 

Therefore, I would not recommend clearing the TPM, deleting Secure Boot keys, reinstalling Windows, rebuilding the EFI boot files, or attempting an unofficial BIOS.

 

None of those procedures can add missing firmware functionality.

 

My conclusion also leads me to state:

 

Your diagnostics strongly suggest a firmware/measured-boot compatibility limitation on the OMEN 875/84FD platform, rather than an incorrectly configured TPM or Secure Boot installation. Unfortunately, there is currently no HP-supported firmware fix available, and it is exceedingly unlikely that HP will create a BIOS update for your legacy platform either.

 

I would leave F.35, TPM 2.0, and Secure Boot enabled and avoid further destructive troubleshooting. At this point in time, a definitive solution would require either an HP firmware update or a change by the game's anti-cheat software to accommodate this older platform.

 

Sorry, this is not what you would like to hear, but we don't want to keep you hanging.

 

Kind Regards,

 

NonSequitur777


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->