• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended

I'm a little confused.  Secure Boot Configuration is under "Advanced" heading on my machine.  Sure Start is Under "Security".  I followed the instructions, but, after enabling Secure Boot, the same screens appeared as before that I posted.  I'm not having very much success with the process. Sorry.

HP Recommended

@jeobsplyr,

 

Hello my friend!

 

Excellent — and please don't apologize. Your BitLocker result is exactly what we wanted:

 

FullyDecrypted / Off

 

So, we're safe to proceed.

 

However, I want to correct our previous direction: do not reset or clear the Secure Boot keys again. Your 840 G5's problem appears to be the known firmware issue preventing the 2023 Secure Boot certificate update, and we now have evidence that this can be addressed manually.

 

For now, leave the BIOS exactly as it is:

 

  • Legacy Support: Disabled
  • Secure Boot: Disabled

 

Windows should boot normally.

 

One thing only for the next step:

 

Open PowerShell as Administrator and run:

Get-SecureBootUEFI -Name PK -Decoded

 

Please send me the complete output.

 

That's it. Don't change anything in BIOS and don't import or clear any keys yet.

 

I need the existing Platform Key (PK) information so we can identify the correct certificate-update procedure for your particular Q78 01.31.00 firmware.

 

We're finally moving from diagnosis to the actual repair.

 

Kind Regards,

 

NonSequitur777


HP Recommended

Alright my Friend,  a little "hiccup" there, but, I'm not deterred.  Will continue to push forward with you.  Here are the results you requested:

 

 

PS C:\WINDOWS\system32> Get-SecureBootUEFI -Name PK -Decoded


SignatureOwner : f5a96b31-dba0-4faa-a42a-7a0c9832768e
Subject : O=HP Inc., C=US, OU=CODE-SIGN, CN=HP UEFI Secure Boot PK 2017
Version : 3
Algorithm : sha256RSA
SerialNumber : 5FB660D4C2FB166B6576B7257A4C37AB
ValidFrom : 2017-01-19 19:00:00Z
ValidTo : 2033-01-16 18:59:59Z

 

Hope this brings us into the "home stretch".  Await your response!!  PEACE!!

HP Recommended

@jeobsplyr,

 

On it -Hello my friend!

 

YES — this is the result we needed, and it is actually very encouraging.

 

Your machine has:

 

HP UEFI Secure Boot PK 2017
BIOS Q78 01.31.00

 

That is the same configuration reported by another EliteBook 840 G5 owner who successfully completed the 2023 Secure Boot certificate update.

 

And here's the important part:

 

We are NOT going to replace your HP Platform Key.

 

That other 840 G5 owner reported that the PK replacement was rejected by the HP firmware -but the remaining certificate updates were accepted, and the machine successfully received the 2023 certificates.

 

So your 2017 HP PK is not the obstacle.

 

Our next step:

 

Before we change anything, I want to verify one thing:

 

Please run this in Administrator PowerShell:

([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI kek).Bytes) -match 'Microsoft Corporation KEK 2K CA 2023')

 

Send me the result.

 

That's all for now.

 

Do not change anything in BIOS.
Do not clear the keys.
Do not enable Secure Boot yet.

 

If that returns False — which I expect — then we have identified the missing piece: the Microsoft 2023 KEK.

 

And that is precisely the certificate the successful 840 G5 procedure says is the critical one.

 

We're getting very close now, my friend.

 

Kind Regards,

 

NonSequitur777


HP Recommended

Okay My Friend, I have results for you:

 

PS C:\WINDOWS\system32> ([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI kek).Bytes) -match 'Microsoft Corporation KEK 2K CA 2023')
False

 

Await your guidance. PEACE!

HP Recommended

@jeobsplyr,

 

Hello my friend!

 

YES — this is an important result.

 

Microsoft Corporation KEK 2K CA 2023 = False means the 2023 KEK is not currently installed in the active Secure Boot KEK database.

 

That fits perfectly with the Event 1802 errors we've been seeing.

 

But don't change anything yet. We're going to make one final check before touching the firmware.

 

Please run this in Administrator PowerShell:

 

([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI KEKDefault).Bytes) -match 'Microsoft Corporation KEK 2K CA 2023')

 

Send me the result — True or False.

 

That's all I need right now.

 

If it returns True, the certificate is already in the firmware's default KEK store and we have a much safer path forward.

 

If it returns False, we'll know the 2023 KEK isn't present there either, and I'll give you the next step based on that result.

 

No BIOS changes. No clearing keys. No certificate imports yet.

 

We're doing this one step at a time now.

 

PEACE, my friend!

 

Kind Regards,

 

NonSequitur777


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->