• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Common problems for Battery
We would like to share some of the most frequently asked questions about: Battery Reports, Hold a charge, Test and Calibrating Battery . Check out this link: Is your notebook plugged in and not charging?
HP Recommended
HP EliteBook 840 G5 Base Model Notebook PC

Hi!
I’ve received this message regarding users of the HP EliteBook 840 G5:
"Secure Boot certificate updates are not supported on your device. To meet the university's security requirements, the device needs to be replaced. Please check the current Secure Boot support status for your model and contact your IT technician or the IT Service Desk before October 1st."
Is there any way to fix this? I have three of these units in use.

 

I am also concerned about potential issues with the HP EliteBook 840 G6, as we have 26 of them in use. Replacing all of them at once would be a massive expense!


Here is a list of the HP models we currently have in use (the 840 G1 is being phased out shortly).
Can you tell me if there are any others that do not support the Secure Boot update?

 

HP EliteBook 6 G1a 14 inch Notebook AI PC
HP EliteBook 6 G1i 13 inch Notebook AI PC
HP EliteBook 645 14 inch G9 Notebook PC
HP EliteBook 665 16 inch G11 Notebook PC
HP EliteBook 8 G1i 14 inch Notebook Next Gen AI PC
HP EliteBook 830 G7 Notebook PC
HP EliteBook 830 G8 Notebook PC
HP EliteBook 840 14 inch G10 Notebook PC
HP EliteBook 840 14 inch G11 Notebook PC
HP EliteBook 840 14 inch G9 Notebook PC
HP EliteBook 840 G1
HP EliteBook 840 G3
HP EliteBook 840 G5
HP EliteBook 840 G6
HP EliteBook 840 G7 Notebook PC
HP EliteBook 840 G8 Notebook PC
HP EliteBook 845 14 inch G10 Notebook PC
HP EliteBook 865 16 inch G10 Notebook PC
HP ProBook 445 14 inch G9 Notebook PC
HP ProBook 450 15.6 inch G10 Notebook PC
HP ProBook 455 15.6 inch G9 Notebook PC


/Jonas

1 REPLY 1
HP Recommended

@j_o_n_a_s,

 

Welcome to our HP Community forum!

 

I would not replace the EliteBook 840 G5s yet. There is an important distinction between "the normal Windows Secure Boot certificate update path is not available" vs. "the computer cannot be updated to support the 2023 certificates."

 

HP has specifically addressed the EliteBook 840 G5 and G6 in Microsoft's OEM Secure Boot Office Hours:

 

  • EliteBook 840 G6: HP has published BIOS 01.36.00 (SP174025), which allows Microsoft to add the 2023 Secure Boot certificates to the system.

  • EliteBook 840 G5: HP states that, because the G5 is now end-of-service, there is a separate HP update package that manually adds the 2023 Secure Boot certificates to the KEK and db databases. HP notes that this package does not update the default databases and instructs customers to contact HP Support to obtain it.

 

So, the three 840 G5 systems should not automatically be considered candidates for replacement. I would first contact HP Support and specifically ask for the Secure Boot 2023 certificate update package for the EliteBook 840 G5.

 

For your 26 EliteBook 840 G6 systems, I would first make sure they are running the latest BIOS 01.36.00 and then allow Windows to complete the Secure Boot certificate transition.

 

For the remainder of your fleet, I would also be cautious about treating the university's message as a blanket indication that older HP hardware is unsupported. Your newer EliteBook/ProBook systems are considerably less concerning, whilst the 840 G1 and 840 G3 are the models in your list I would regard as the most likely to require replacement or special handling. The 840 G5 is an interesting exception because HP has provided a specific certificate-update mechanism despite its age.

 

You can also check an individual Windows system rather than relying solely on the model name. In an elevated PowerShell window:

 

([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).Bytes) -match 'Windows UEFI CA 2023')

 

A result of True indicates that the Windows UEFI CA 2023 certificate is already present in the Secure Boot db.

 

I would also recommend checking the KEK for the Microsoft 2023 certificate, because having the Windows UEFI CA 2023 in db is only part of the transition.

 

In short: I would not replace the 3 × 840 G5 or 26 × 840 G6 systems based solely on that message. The G6 is explicitly supported, and HP has provided a specific update path for the G5. I would first establish the BIOS/certificate status of a representative machine from each model family and then deal with any genuine exceptions individually.

 

Kind Regards,

 

NonSequitur777


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->