• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended
HP EliteBook 840 G5

@jeobsplyr,

 

I am posting your HP EliteBook 840 G5 issue/question you posted in the HP Pavilion 590-p0054 discussion in a brand-new discussion thread -and I quote:

 

Just thought I'd give you a brief explanation of what is the issue with my Elitebook 840 G5. I tried to manually install the 2023 secure boot certificates, after perusing some methods on the Net. I found one I thought would be pretty easy. Well, the install didn't go well and I tried reverting bios changes I made for the install. When rebooting, got the f30 error with secure boot enabled. So I disabled both legacy and secure boot supports. I can boot into windows. Need to correct the error. Let me know when you're available. PEACE!!

 

It makes sense to dedicate a separate discussion thread for your EliteBook 840 G5!

 

And here we go:

 

Good evening again, my friend!

 

Well, you've just given me something extremely important -and I'm actually glad you told me the complete story before we start changing anything on the EliteBook.

 

And after what we just went through with the Pavilion, I'm going to be especially careful with this one. 😊

 

First: DON'T change anything else in the BIOS for now.

 

The fact that you can currently boot Windows with:

 

Legacy Support: Disabled

 

and

 

Secure Boot: Disabled

 

is very good news.

 

It means the machine is not bricked, and we have a functioning Windows installation from which we can gather information.

 

The F30 error appearing immediately after your attempt to install the 2023 Secure Boot certificates is also a very significant clue.

 

Unlike the Pavilion, I don't want to assume this is a Windows boot-file problem.

 

In fact, based on what you've told me so far, I'm much more suspicious of the UEFI Secure Boot configuration/certificate state in the EliteBook's firmware.

 

And there's another important distinction:

 

Please do not try the certificate installation procedure again.

 

Not yet, anyway.

 

I want to see exactly what state the firmware is in before we attempt to repair anything.

 
Here's what I want to do first:
 

We're going to take the same approach that worked so well with the Pavilion:

 

diagnose first — modify second.

 

Since Windows currently boots, that's our opportunity to collect information safely.

 

I want to establish:

 

  1. Exactly what BIOS version the EliteBook is running.
  2. What HP reports for Secure Boot configuration.
  3. Whether Windows currently sees Secure Boot as supported and/or enabled.
  4. Whether the Secure Boot Platform Key (PK) is present.
  5. Whether the KEK, db, and dbx databases are present.
  6. Exactly what Windows reports about the F30 condition.

 

We are not going to clear keys.

We are not going to load/delete keys.

We are not going to reset Secure Boot to factory defaults yet.

We are not going to flash the BIOS yet.

 

And absolutely do not select anything labeled "Clear Secure Boot Keys".

 

We've learned enough from our previous HP cases to know that Secure Boot key management deserves a very deliberate approach.

 
I need some information from the EliteBook first.
 

When you're ready, boot normally into Windows with Secure Boot disabled.

 

Then please send me the following.

 

1. System Information:

 

Press:

 

Windows key + R

 

type: msinfo32

 

and press Enter.

 

Please give me the values for:

 

BIOS Mode

BIOS Version/Date

Secure Boot State

OS Name

OS Version

 

If it's easier, a photograph/screenshot of the System Summary screen is perfectly fine.

 
2. PowerShell — Secure Boot status:
 

Open PowerShell as Administrator and run:

 

Confirm-SecureBootUEFI

 

Tell me exactly what it returns.

 

Then run:

 

Get-SecureBootUEFI

 

and post the complete output.

 

If that produces an error, don't try to fix the error — just give me the exact wording.

 
3. TPM information:
 

Still in elevated PowerShell, run: Get-Tpm

 

and post the complete result.

 
4. Most importantly — tell me exactly what F30 says.
 

If you can reproduce the F30 screen without changing anything, I would like the exact wording of the error.

 

A photograph of the F30 screen would be even better.

 

Don't intentionally trigger the error yet, though.

 

If you already have a photograph of it from when this happened, send that instead.

 
And one more thing...
 

You mentioned that you found a method online for manually installing the 2023 Secure Boot certificates.

When you have a moment, please give me either:

 

  • the URL of the procedure you followed, or
  • the name/title of the article or instructions.

 

That could be extremely useful.

 

I don't want to criticize the procedure before seeing it. There are several different Secure Boot certificate-update mechanisms, and the exact method matters enormously -particularly with older HP firmware.

 

Your EliteBook 840 G5 is also from a generation where the firmware's Secure Boot implementation and the newer Microsoft certificate transition need to be handled carefully.

 

So, I'd like to reconstruct exactly what was changed rather than guessing.

 
Most importantly:
 

You did the right thing by stopping.

 

You discovered the F30 error, disabled Secure Boot, got Windows booting again, and came to me before attempting another repair.

 

That's exactly what I wanted you to do.

 

The Pavilion taught us a valuable lesson:

 

Don't repair what we haven't diagnosed.

 

This time we're going to follow that rule from the very beginning.

 

And don't worry about availability, my friend.

 

I'm here.

 

Bring me the EliteBook's information when you're ready, and we'll start from the machine's current known-good state and work forward carefully.

 

No rush.

 

No random BIOS changes.

No clearing keys.

No BIOS flashing.

 

Just information first.

 

Then we'll determine exactly what F30 is telling us and formulate the safest path back to Secure Boot.

 

PEACE, MY GOOD FRIEND! 🤝

 

And congrats again on the Pavilion victory. Now let's see if we can get your EliteBook back into shape without creating another adventure quite as long as the last one!

 

Kind Regards,

 

NonSequitur777


6 REPLIES 6
HP Recommended

I will get the information to you tomorrow.  Guess I retire more earlier now that I'm older..LOL!  So, I'll get you the info tomorrow, if that's okay.  I do know the forum where I got the info for manually installing the 2023 secure boot certificates.  Site was Eleven Forum, a post is there under jeobsplyr, dated 8/12/26.  Like I said, I tried it, maybe I shouldn't have, and it did not work.  Trust me, I will not attempt it again.  Will touch base with you tomorrow. PEACE!!

HP Recommended

@jeobsplyr,

 

There is absolutely no rush!

 

Kind Regards,

 

NonSequitur777


HP Recommended

Good Afternoon My Friend, I'm here again!  I hope you are well and prospering!  Think I'm ready to begin another "journey" in solving my f30 error.  I have gathered the information you asked for and maybe some additional information that may assist you moving forward.  BTW, I gave doing screenshots a try, but, it didn't go very well, sorry. So, I'm back to text results. Here goes:

 

1.  System Information:

OS Name Microsoft Windows 11 Pro
Version 10.0.26200 Build 26200
Other OS Description Not Available
OS Manufacturer Microsoft Corporation
System Name JAMES-NEW-ELITE
System Manufacturer HP
System Model HP EliteBook 840 G5
System Type x64-based PC
System SKU 4NH98US#ABA
Processor Intel(R) Core(TM) i5-8350U CPU @ 1.70GHz, 1896 Mhz, 4 Core(s), 8 Logical Processor(s)
BIOS Version/Date HP Q78 Ver. 01.31.00, 3/10/2025
SMBIOS Version 3.1
Embedded Controller Version 4.112
BIOS Mode UEFI
BaseBoard Manufacturer HP
BaseBoard Product 83B2
BaseBoard Version KBC Version 04.70.00
Platform Role Mobile
Secure Boot State Off
PCR7 Configuration Elevation Required to View
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "10.0.26100.1"
User Name JAMES-NEW-ELITE\jeobs
Time Zone Eastern Daylight Time
Installed Physical Memory (RAM) 32.0 GB
Total Physical Memory 31.8 GB
Available Physical Memory 24.4 GB
Total Virtual Memory 33.8 GB
Available Virtual Memory 26.9 GB
Page File Space 2.00 GB
Page File C:\pagefile.sys
Kernel DMA Protection Off
Virtualization-based security Running
Virtualization-based security Required Security Properties
Virtualization-based security Available Security Properties Base Virtualization Support, DMA Protection, UEFI Code Readonly, SMM Security Mitigations 1.0, Mode Based Execution Control
Virtualization-based security Services Configured Hypervisor enforced Code Integrity
Virtualization-based security Services Running Hypervisor enforced Code Integrity
App Control for Business policy Enforced
App Control for Business user mode policy Off
Automatic Device Encryption Support Elevation Required to View
A hypervisor has been detected. Features required for Hyper-V will not be displayed.

 

2.  Confirm Secure Boot UEFI:

PS C:\WINDOWS\system32> Confirm-SecureBootUEFI
False

 

3.  Get-Secure Boot UEFI

PS C:\WINDOWS\system32> Get-SecureBootUEFI

cmdlet Get-SecureBootUEFI at command pipeline position 1
Supply values for the following parameters:
Name:
Get-SecureBootUEFI : Cannot validate argument on parameter 'Name'. The argument "" does not belong to the set
"PK,KEK,db,dbx,SetupMode,SecureBoot,PKDefault,KEKDefault,dbDefault,dbxDefault,dbt,dbtDefault" specified by the
ValidateSet attribute. Supply an argument that is in the set and then try the command again.
At line:1 char:1
+ Get-SecureBootUEFI
+ ~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidData: (:) [Get-SecureBootUEFI], ParameterBindingValidationException
+ FullyQualifiedErrorId : ParameterArgumentValidationError,Microsoft.SecureBoot.Commands.GetSecureBootUefiCommand

 

4.  Get-TPM

PS C:\WINDOWS\system32> Get-Tpm


TpmPresent : True
TpmReady : True
TpmEnabled : True
TpmActivated : True
TpmOwned : True
RestartPending : False
ManufacturerId : 1229346816
PpiVersion : 1.3
ManufacturerIdTxt : IFX
ManufacturerVersion : 7.63.3353.0
ManufacturerVersionFull20 : 7.63.3353.0
ManagedAuthLevel : Full
OwnerAuth :
OwnerClearDisabled : False
AutoProvisioning : Enabled
LockedOut : False
LockoutHealTime : 2 hours
LockoutCount : 20
LockoutMax : 32
SelfTest : {}

 

Also I found the pics I took when the F30(3F0) error first occurred.  

1.

Hard Boot Disk Not FoundHard Boot Disk Not Found20260822_121137.jpg20260822_121137.jpg20260822_121216.jpg20260822_121216.jpg20260822_121546.jpg20260822_121546.jpg

 

I also thought I'd include the site URL where I got the information to manually install the 2023 certificates. Which is:  https://www.elevenforum.com/t/why-installing-2023-secure-boot-certificates-manually-on-hp-elitebook-....  Which I WILL refrain from doing again, unless I get your guidance.  Not of great importance right now, just getting this error solved.  I hope this isn't TOO much info at one time. I tried to give you as much as I could to get started. I look to hear   from you soon. PEACE, MY FRIEND!!!

HP Recommended

Good Morning My Friend. Hope you are well!! Awaiting your input on the issue with my laptop. I know the last issue was long, hopefully this will be much shorter. Ready when you are! Chat with you soon! PEACE!!

HP Recommended

@jeobsplyr,

 

Yea, I don't always get a notification email from HP when OPs post a (new) message -hence the delay.

 

In any regards, a very Good morning for you, my friend! And please don't apologize for the screenshots. They were actually extremely helpful. In fact, one of them gave us a very important clue that changes how I want to approach this problem.

 

I have now gone through everything you provided, including the photographs.

 

First, we have an important clarification:

 

The error is 3F0, not F30:

 

Boot Device Not Found

Hard Disk - (3F0)

 

But even more important is the other message you captured:

 

Selected boot image did not authenticate.

 

That is the clue I've been looking for.

 

Because Windows boots normally when Secure Boot is disabled, while enabling Secure Boot results in the authentication failure/3F0 condition, I am now much more suspicious of the Secure Boot key/certificate state than I am of your Windows installation or SSD.

 

Your SSD diagnostics also passed, which is reassuring.

 

So, at this point:

 

DO NOT reinstall Windows.
DO NOT rebuild the BCD.
DO NOT run BCDBOOT.
DO NOT clear the Secure Boot keys.
DO NOT repeat the 2023 certificate procedure.
DO NOT flash the BIOS.

 

We're going to diagnose the Secure Boot state first.

 

Your BIOS information is also very useful

 

You are running:

 

HP EliteBook 840 G5
Motherboard: HP 83B2
BIOS: Q78 Ver. 01.31.00 — 03/10/2025
BIOS Mode: UEFI
Secure Boot State: Off

 

That's exactly the information I wanted.

 

And your TPM looks completely healthy:

 

  • TPM Present: True
  • TPM Ready: True
  • TPM Enabled: True
  • TPM Activated: True
  • TPM Owned: True
  • Restart Pending: False
  • Manufacturer: Infineon
  • Firmware: 7.63.3353.0

 

So we're going to leave the TPM alone. It isn't where I want to concentrate our attention.

 

One small correction regarding Get-SecureBootUEFI

 

The command you entered wasn't actually telling us that Secure Boot was broken.

 

Get-SecureBootUEFI requires you to specify which UEFI variable you want to examine. PowerShell even gave us the list of valid names.

 

That's actually perfect, because now we can inspect the individual Secure Boot components.

 

Please boot normally into Windows with Secure Boot still disabled.

 

Then open PowerShell as Administrator and run these commands one at a time:

 

Get-SecureBootUEFI -Name PK

Get-SecureBootUEFI -Name KEK

Get-SecureBootUEFI -Name db

Get-SecureBootUEFI -Name dbx

Get-SecureBootUEFI -Name SetupMode

Get-SecureBootUEFI -Name SecureBoot

 

Please copy/paste the complete output from all six commands.

 

If any command produces an error, that's perfectly fine. Do not try to correct the error. Just include the exact error message.

 

I also want one additional check:

 

Please run:

 

reg query "HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot" /s

 

You can run that from either an elevated Command Prompt or PowerShell.

 

Again, we are only reading information.

 

Don't change anything in the registry.

 

Why I'm asking for these particular results:

 

We're trying to answer six very specific questions:

 

  1. Is the Platform Key (PK) present?
  2. Is the Key Exchange Key (KEK) present?
  3. Are the Microsoft/UEFI allowed-signature database (db) and forbidden-signature database (dbx) present?
  4. Is the firmware in Setup Mode?
  5. Does the firmware report Secure Boot as enabled internally?
  6. What does Windows know about the Secure Boot configuration/update state?

 

That will tell us considerably more than simply knowing that Windows currently reports Secure Boot as Off.

And because your problem began immediately after attempting the 2023 certificate installation, I particularly want to see whether the PK/KEK/db/dbx relationship is intact.

 

One very important observation:

 

The sequence you've described now makes sense:

 

Windows boots normally → 2023 certificate procedure attempted → Secure Boot subsequently rejects the boot image → "Selected boot image did not authenticate" → 3F0 → Secure Boot disabled → Windows boots again.

 

That strongly suggests that the underlying Windows installation may be perfectly healthy and that the failure occurs specifically when the firmware attempts to authenticate the Windows bootloader.

 

That's good news, because it gives us a much narrower problem to solve.

 

And I'm particularly glad you stopped rather than continuing to experiment with the Secure Boot keys.

 

The EliteBook 840 G5 is old enough that we need to be particularly careful about applying procedures designed for newer HP systems. The 2023 Secure Boot certificate transition is not something I want us to approach by trial and error.

 

So for now, my friend, nothing gets changed.

 

Just give me the output from those two diagnostic checks.

 

Once I see the PK, KEK, db, dbx, SetupMode, SecureBoot, and registry results, we'll know what state the firmware is actually in.

 

Then -and only then- we'll decide what the safest repair is.

 

And again, excellent job gathering all of this information. This time we're not guessing. We're narrowing the problem down one piece at a time.

 

Kind Regards,

 

NonSequitur777


HP Recommended

Good to hear from you my friend! I will get everything done and posted later on! Got my grandson here while his Mom works at her office today! He's a  "handful"! So, look for the results this evening. PEACE!!

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->