• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended

@jeobsplyr,

 

My Friend — STOP! We have the breakthrough, but it isn't quite the one we hoped for.

 

First, don't worry about the mountvol S: /D message. That simply means there was no S: mount remaining for Windows to remove. It did not damage anything.

 

Now let's look at the VERY important photograph.

 

The first screen says:

 

"Selected boot image did not authenticate."

 

THAT is our smoking gun.

 

We have already independently proven that bootmgfw.efi exists on your EFI System Partition and that Windows considers its Microsoft Authenticode signature Valid.

 

Therefore, Windows has a legitimate Microsoft-signed bootloader.

 

But when the HP firmware's Secure Boot verifier examines that bootloader, the firmware rejects it.

 

That means our problem is no longer BCD, Windows, the SSD, GPT, or the EFI System Partition.

 

We are now squarely in the HP UEFI Secure Boot trust configuration.

 

And this makes the earlier KI_7 event extremely significant:

 

"The Secure Boot update KEK 2023 was blocked due to a known firmware issue on the device."

 

We now have two independent pieces of evidence pointing to the same area.

 

BUT — we're not going to start randomly changing keys.

 

I want to do this carefully because you previously attempted the 2023 Secure Boot certificate update, and I don't want us making the situation worse.

 

Please leave Secure Boot DISABLED for the moment so Windows can boot.

 

Then enter BIOS with F10 and go to:

 

Security → Secure Boot Configuration

 

STOP THERE.

 

Take another clear photograph of that entire Secure Boot Configuration screen and post it for me.

 

Do NOT select Clear Secure Boot Keys.

Do NOT delete PK, KEK, db, or dbx.

Do NOT change TPM settings.

Do NOT select Restore Security Settings to Factory Defaults yet.

 

I want to see exactly which Secure Boot recovery/key-management options your particular Q78 BIOS provides before we touch anything.

 

We're very close now, my friend.

 

And I want you to notice something important:

 

Secure Boot OFF → Windows boots normally.

Secure Boot ON → HP firmware says "Selected boot image did not authenticate."

 

Meanwhile:

 

Microsoft bootmgfw.efi → Valid signature.

 

That is an exceptionally clean diagnostic chain.

 

We aren't guessing anymore.

 

The HP firmware is rejecting a bootloader that Windows has verified as legitimately Microsoft-signed.

 

Now we're going to repair the trust configuration, not Windows.

 

One step at a time. No key deletion yet.

 

Onward and Upward, my friend! PEACE!!!

 

Kind Regards,

 

NonSequitur777


HP Recommended

Good Evening My Friend.  I took a photo of my BIOS Secure Boot Configuration screen;

 

jeobsplyr_0-1788224168654.jpeg

 Also, as you can see, it is under the " Advanced " tab.  Hopefully, something can be ascertained from this.  Chat with you soon!!  PEACE!!

HP Recommended

@jeobsplyr,

 

I carefully went through the information you just provided, and this is the most useful BIOS information we've obtained yet.

 

First:

 

We don't want to change "Enable MS UEFI CA Key."

 

It is already checked, which is exactly what we want.

 

So that setting is not our problem.

 

The reason all four Secure Boot Key Management options are greyed out is also now clear.

 

Your BIOS explicitly says:

 

"Access to the above settings requires Sure Start Secure Boot Keys Protection to be disabled."

 

In other words, HP Sure Start is currently protecting your Secure Boot key database from modification.

 

And HP's own documentation confirms this behavior.

 

This is actually good news.

 

We now know why we couldn't get to the key-management functions.

 

And I believe the next step is to restore the factory Secure Boot keys, rather than clearing them or trying to manually install more certificates.

 

BUT — we are going to do this carefully.

 

First, stay in Windows with Secure Boot DISABLED.

 

Before changing anything, I want you to run one final read-only check so we don't get surprised by BitLocker when we eventually turn Secure Boot back on.

 

In Administrator PowerShell, please run:

 

Get-BitLockerVolume -MountPoint C: | Select-Object MountPoint,VolumeStatus,ProtectionStatus,KeyProtector

 

Send me the complete result.

 

Do not change anything in BIOS yet.

 

Once we see that result, I want you to enter BIOS and go to:

 

Security → BIOS Sure Start

 

We are looking for:

 

Sure Start Secure Boot Keys Protection

 

Do NOT change anything else.

 

Take a photograph of that screen and send it to me.

 

HP's documented procedure for accessing the Secure Boot key-management controls requires this protection to be disabled first.

 

We are NOT going to use "Clear Secure Boot Keys."

 

Our intended operation is:

 

Reset Secure Boot Keys to Factory Defaults

 

because that restores the factory Secure Boot trust configuration rather than simply deleting the keys.

 

But I want to see your BIOS Sure Start screen first so we can make absolutely certain we're changing the correct protection setting on your particular 840 G5.

 

And remember:

 

Enable MS UEFI CA Key = already checked → GOOD.

Legacy Support Disabled → GOOD.

Windows bootloader signature Valid → GOOD.

Windows boots with Secure Boot disabled → GOOD.

 

The remaining problem is the firmware's Secure Boot trust configuration.

 

My friend, I think we are finally at the point where we're going to fix the configuration rather than merely diagnose it.

 

One more careful step. Then we make the change.

 

No CLEAR. No deleting keys. No reinstalling Windows.

 

Kind Regards,

 

NonSequitur777


† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->