• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended
HP ProDesk 600 G4 Small Form Factor PC
Microsoft Windows 11

I own a 2018 HP ProDesk 600 G4 SFF (Baseboard 83EE) running BIOS Q07 v02.30.00 and for weeks now have been unable to install the latest "2023 Windows UEFI CA secure boot certificate". I have tried all the workarounds (manual installs) that I could find on the internet. I ran across this statement:


"The HP ProDesk 600 G4 SFF (Baseboard 83EE) running BIOS Q07 v02.30.00 already contains the baseline firmware update needed to support the Microsoft Secure Boot transition. However, there is a known firmware issue on this specific generation that prevents the 2023 Windows UEFI CA certificate from successfully applying, even with this version installed." and "Because Microsoft's enforcing deadline for mandatory certificate updates runs up against a hard stop, HP is releasing a follow-up revision beyond v02.30.00 specifically to address the broken database append problem on G4/G5 units. Check the HP Software and Driver Downloads page periodically over the next month for a version like v02.31.00 or higher."

Both of these were published back in the March 2026 timeframe.

My questions. 1) Does anyone else have this exact same HP model and has been able to install the 2024 secure boot cert? If so, how? 2) Has anyone been informed directly via HP support that there is indeed a new BIOS coming to fix this issue?

5 REPLIES 5
HP Recommended

Hi  @tg3138 
 
Welcome to the HP Support Community!

Thank you for reaching out and for providing the detailed information regarding your HP ProDesk 600 G4 Small Form Factor PC. I understand you're looking into the Secure Boot certificate update and BIOS compatibility.

To better assist you, could you kindly confirm the below details : 

  • Have you received any specific error message or error code when attempting to install the Secure Boot certificate update?
  • Have you checked whether TPM 2.0 is enabled and recognized correctly in Windows Security?
  • Is Secure Boot currently enabled in the BIOS?

In the meantime, Kindly try the below steps and confirm : 

  1. Verify BIOS Defaults
    • Restart the PC and enter BIOS Setup (F10).
    • Load BIOS default settings.
    • Save changes and reboot.
  2. Confirm Secure Boot Status
    • Press Windows + R, type msinfo32, and press Enter.
    • Verify that: 
      • BIOS Mode = UEFI
      • Secure Boot State = On
  3. Check for Pending Windows Updates
    • Install all available Windows 11 Optional and security updates.
    • Restart the system after updates are completed.

Regarding the information you found about a potential BIOS revision beyond v02.30.00, if HP has published a newer BIOS for your specific model, it would appear on the HP Software and Driver Downloads page - https://support.hp.com/in-en  for your product.

 

I hope this helps. 

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

HP Recommended

Have you received any specific error message or error code when attempting to install the Secure Boot certificate update?

I get a system error in the event logs (1802).

I also have the Windows security message

"Devices in this group are affected by a known issue. To reduce risk,
Secure Boot certificate updates are temporarily paused while Microsoft
and partners work toward a supported resolution,"

 

Have you checked whether TPM 2.0 is enabled and recognized correctly in Windows Security? Yes, it is set
Is Secure Boot currently enabled in the BIOS? Yes, it is

Verify BIOS Defaults
Restart the PC and enter BIOS Setup (F10).
Load BIOS default settings.
Save changes and reboot. Done


Confirm Secure Boot Status
Verify that:
BIOS Mode = UEFI set to UEFI
Secure Boot State = On is set On


Check for Pending Windows Updates - All updates are installed


Based on all my research this particular HP desktop is in need of a BIOS update
to except the 2023 certificate. Just trying to confirm that is true or if I
should keep looking for an issue on my HP ProDesk 600 G4 SFF.

HP Recommended

Hi @tg3138,

Thank you for providing the detailed update and for completing all the requested checks. I appreciate the effort. 

Based on the information you shared:

  • TPM 2.0 is enabled and recognized correctly.
  • Secure Boot is enabled.
  • The system is configured for UEFI boot mode.
  • BIOS defaults have been loaded and tested.
  • Windows is fully updated.
  • You are still seeing Event ID 1802 and the Windows notification indicating that Secure Boot certificate updates are paused.

Given that all prerequisite settings are already configured correctly, there are no additional Windows or BIOS configuration steps .  Therefore, based on the troubleshooting completed, If a newer BIOS revision becomes available for your HP ProDesk 600 G4 SFF, I would recommend installing it and check whether Windows offers the Secure Boot certificate update again.


Regards

Deep_World

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

HP Recommended

Thank you very much for the information.   I take your reply to be that this particular 2018 HP Prodesk 600 G4 SFF does require a BIOS update to install the 2023  MS certs.   At this time it is unknown if HP will ever provide such an update as to allow the  install of the new 2023 MS certs.    There is no "work around"  that I as a customer can do to force the installation of the 2023 MS certs.    Again, Thank you.

HP Recommended

Hi @tg3138,


Thank you for the update and for taking the time to thoroughly test and verify all the recommended settings. I appreciate the detailed information you've provided.

Based on the checks you've completed, including confirming TPM 2.0, Secure Boot, UEFI mode, BIOS defaults, and fully updated Windows, it appears that there are no additional user-accessible settings available to further troubleshoot the Secure Boot certificate update on your system.

 

As this concerns BIOS and Secure Boot certificate compatibility, To get you the best assistance, we need to take this conversation to a private chat. We're inviting you to a private message to protect your privacy and ensure that any sensitive information remains confidential. 

 

To access your private message, just click the little blue envelope icon on the upper right corner of your HP Community profile, next to your profile name. Alternatively, you can click on this link. 

You can use this link as well: 

Private Messages - HP Support Community

 

 

We're looking forward to helping you resolve this issue! 

 

Stay tuned, and thanks for your patience! 

 

Regards,

Deep_World

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->