• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended

@jeobsplyr,

 

My Friend — STOP! We have the breakthrough, but it isn't quite the one we hoped for.

 

First, don't worry about the mountvol S: /D message. That simply means there was no S: mount remaining for Windows to remove. It did not damage anything.

 

Now let's look at the VERY important photograph.

 

The first screen says:

 

"Selected boot image did not authenticate."

 

THAT is our smoking gun.

 

We have already independently proven that bootmgfw.efi exists on your EFI System Partition and that Windows considers its Microsoft Authenticode signature Valid.

 

Therefore, Windows has a legitimate Microsoft-signed bootloader.

 

But when the HP firmware's Secure Boot verifier examines that bootloader, the firmware rejects it.

 

That means our problem is no longer BCD, Windows, the SSD, GPT, or the EFI System Partition.

 

We are now squarely in the HP UEFI Secure Boot trust configuration.

 

And this makes the earlier KI_7 event extremely significant:

 

"The Secure Boot update KEK 2023 was blocked due to a known firmware issue on the device."

 

We now have two independent pieces of evidence pointing to the same area.

 

BUT — we're not going to start randomly changing keys.

 

I want to do this carefully because you previously attempted the 2023 Secure Boot certificate update, and I don't want us making the situation worse.

 

Please leave Secure Boot DISABLED for the moment so Windows can boot.

 

Then enter BIOS with F10 and go to:

 

Security → Secure Boot Configuration

 

STOP THERE.

 

Take another clear photograph of that entire Secure Boot Configuration screen and post it for me.

 

Do NOT select Clear Secure Boot Keys.

Do NOT delete PK, KEK, db, or dbx.

Do NOT change TPM settings.

Do NOT select Restore Security Settings to Factory Defaults yet.

 

I want to see exactly which Secure Boot recovery/key-management options your particular Q78 BIOS provides before we touch anything.

 

We're very close now, my friend.

 

And I want you to notice something important:

 

Secure Boot OFF → Windows boots normally.

Secure Boot ON → HP firmware says "Selected boot image did not authenticate."

 

Meanwhile:

 

Microsoft bootmgfw.efi → Valid signature.

 

That is an exceptionally clean diagnostic chain.

 

We aren't guessing anymore.

 

The HP firmware is rejecting a bootloader that Windows has verified as legitimately Microsoft-signed.

 

Now we're going to repair the trust configuration, not Windows.

 

One step at a time. No key deletion yet.

 

Onward and Upward, my friend! PEACE!!!

 

Kind Regards,

 

NonSequitur777


HP Recommended

Good Evening My Friend.  I took a photo of my BIOS Secure Boot Configuration screen;

 

jeobsplyr_0-1788224168654.jpeg

 Also, as you can see, it is under the " Advanced " tab.  Hopefully, something can be ascertained from this.  Chat with you soon!!  PEACE!!

HP Recommended

@jeobsplyr,

 

I carefully went through the information you just provided, and this is the most useful BIOS information we've obtained yet.

 

First:

 

We don't want to change "Enable MS UEFI CA Key."

 

It is already checked, which is exactly what we want.

 

So that setting is not our problem.

 

The reason all four Secure Boot Key Management options are greyed out is also now clear.

 

Your BIOS explicitly says:

 

"Access to the above settings requires Sure Start Secure Boot Keys Protection to be disabled."

 

In other words, HP Sure Start is currently protecting your Secure Boot key database from modification.

 

And HP's own documentation confirms this behavior.

 

This is actually good news.

 

We now know why we couldn't get to the key-management functions.

 

And I believe the next step is to restore the factory Secure Boot keys, rather than clearing them or trying to manually install more certificates.

 

BUT — we are going to do this carefully.

 

First, stay in Windows with Secure Boot DISABLED.

 

Before changing anything, I want you to run one final read-only check so we don't get surprised by BitLocker when we eventually turn Secure Boot back on.

 

In Administrator PowerShell, please run:

 

Get-BitLockerVolume -MountPoint C: | Select-Object MountPoint,VolumeStatus,ProtectionStatus,KeyProtector

 

Send me the complete result.

 

Do not change anything in BIOS yet.

 

Once we see that result, I want you to enter BIOS and go to:

 

Security → BIOS Sure Start

 

We are looking for:

 

Sure Start Secure Boot Keys Protection

 

Do NOT change anything else.

 

Take a photograph of that screen and send it to me.

 

HP's documented procedure for accessing the Secure Boot key-management controls requires this protection to be disabled first.

 

We are NOT going to use "Clear Secure Boot Keys."

 

Our intended operation is:

 

Reset Secure Boot Keys to Factory Defaults

 

because that restores the factory Secure Boot trust configuration rather than simply deleting the keys.

 

But I want to see your BIOS Sure Start screen first so we can make absolutely certain we're changing the correct protection setting on your particular 840 G5.

 

And remember:

 

Enable MS UEFI CA Key = already checked → GOOD.

Legacy Support Disabled → GOOD.

Windows bootloader signature Valid → GOOD.

Windows boots with Secure Boot disabled → GOOD.

 

The remaining problem is the firmware's Secure Boot trust configuration.

 

My friend, I think we are finally at the point where we're going to fix the configuration rather than merely diagnose it.

 

One more careful step. Then we make the change.

 

No CLEAR. No deleting keys. No reinstalling Windows.

 

Kind Regards,

 

NonSequitur777


HP Recommended

Good Morning My Friend.  It's early, I'm getting ready for my grandson's visit.  We have him 3 days a week while his Mom goes to the office.  She works from home 2 days a week. But I can get a reply back to you if need be.  Feel free to send any request for additional info.  The results you requested is as follows:

 

1.  

PS C:\WINDOWS\system32> Get-BitLockerVolume -MountPoint C: | Select-Object MountPoint,VolumeStatus,ProtectionStatus,KeyProtector

MountPoint VolumeStatus ProtectionStatus KeyProtector
---------- ------------ ---------------- ------------
C: FullyDecrypted Off {}

 

2.  

jeobsplyr_0-1788263443609.jpeg

 

Look to hear from you later.  PEACE!!

 

HP Recommended

@jeobsplyr,

 

Good Morning, My Friend!

 

Excellent — the BitLocker result is exactly what I wanted to see:

C: FullyDecrypted / Off / {}

 

That means BitLocker is completely out of our way. There is no encryption or recovery-key issue that we need to account for while working on the firmware.

 

We can now see the Sure Start configuration, including Sure Start Secure Boot Keys Protection.

 

This explains why the Secure Boot Key Management controls were previously greyed out. HP is protecting the Secure Boot key database with Sure Start.

 

So we're going to make ONE change — and only one change.

 

With Secure Boot still DISABLED, go back into BIOS with F10 and select:

Security → BIOS Sure Start

 

Locate: Sure Start Secure Boot Keys Protection

 

Change only that setting to Disabled.

 

Do NOT change anything else.

 

In particular:

 

Do NOT Clear Secure Boot Keys
Do NOT Reset Secure Boot Keys yet
Do NOT delete PK, KEK, db or dbx
Do NOT change TPM settings
Do NOT enable Secure Boot yet

 

Save the change and exit BIOS so Windows can boot normally.

 

Then stop.

 

Once back in Windows, you don't need to run another PowerShell command yet.

 

Please go back into BIOS with F10 → Security → Secure Boot Configuration and take another clear photograph of that entire screen.

 

What I specifically want to determine is whether the four previously greyed-out Secure Boot Key Management options are now accessible.

 

Don't select any of them yet.

 

Just let me see the screen first.

 

We're finally narrowing this down to the actual firmware trust mechanism. The BitLocker result is clean, and the Sure Start screen has now given us the missing piece.

 

One change. One photograph. Then we'll decide the next move.

 

Onward and Upward, my friend! PEACE!!

 

Kind Regards,

 

NonSequitur777


HP Recommended

Good Afternoon My Friend.  Would've replied earlier, but, my grandson has been very "active".  So, I gave him lunch and now he's napping.  I did as you instructed, cleared the checkbox on "Sure Start Secure Boot Key Protection".  Saved & exited, allowed Windows to startup.  Restarted and entered BIOS and retrieved this:

 

jeobsplyr_0-1788289709595.jpeg

 

 

Hope this info is sufficient.  I await your further instructions.  PEACE!!

HP Recommended

@jeobsplyr,

 

Good afternoon, my friend — and excellent work! And please tell your grandson that he has impeccable timing.

 

I have carefully examined your new photograph, and this is good information. We have learned something important.

 

First, your change to Sure Start Secure Boot Keys Protection = Disabled was accepted and survived the reboot. Excellent.

 

However, the Secure Boot Key Management controls are still greyed out.

 

And the BIOS itself has now given us the explanation: those controls require BIOS Administrator credentials to be configured AND Secure Boot to be enabled.

 

HP's documentation confirms this requirement.

 

So we are NOT going to touch any of the key-management options yet.

 

In particular:

 

Do NOT select Clear Secure Boot Keys
Do NOT select Reset Secure Boot Keys to factory defaults
Do NOT import any keys
Do NOT delete PK, KEK, db or dbx

 

We now need to determine whether a BIOS Administrator password is already configured.

 

With Secure Boot still DISABLED, please go to: F10 → Security

 

Look for BIOS Administrator Password / Create BIOS Administrator Password (the exact wording can vary slightly with the BIOS revision).

 

Do not create, change, or delete a password yet.

 

I only want you to tell me what the BIOS currently shows there.

 

If possible, take a photograph of the Security screen showing the BIOS Administrator/password section and post it here.

 

One more thing: leave Secure Boot disabled for the moment.

 

We now know that Secure Boot is one of the conditions required to unlock Secure Boot Key Management, but we already know that enabling it previously prevented Windows from booting. I don't want you repeatedly toggling it until we've established the BIOS Administrator credential situation and decided exactly how we're going to proceed.

 

We're getting much closer now. The greyed-out controls are no longer a mystery: Sure Start protection was one lock, and the BIOS is telling us that Secure Boot + BIOS Administrator credentials are the remaining requirements.

 

One photograph of the Security/password section — and nothing else changed.

 

Onward and Upward, my friend! PEACE!!

 

Kind Regards,

 

NonSequitur777


HP Recommended

Good Evening My Friend.  Well, we're free until tomorrow.  Here's a pic of the screen you requested:

 

 

jeobsplyr_0-1788305136116.jpeg

 

Awaiting further instruction.  PEACE!!

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->