Hi George,
I don’t know if you are still having a problem, so I ask AI about it. Here is the response.
Since you’ve tried BIOS reset and “Clear key database” without success, this is likely a firmware-level issue. HP’s BIOS may not restore default Secure Boot keys automatically.
A few options:
Check for BIOS/UEFI updates from HP.
Manually enroll keys if your BIOS supports it (Microsoft PK, KEK, db or Linux shim/MOK).
Contact HP support, as some All-in-One models have firmware limitations.
Windows alone cannot restore Secure Boot keys. Multi-boot setups increase the risk of EFI key corruption, so any fix needs to be at the firmware level.
Hi everyone,
sorry for not responding - had a lot going on.
Thanks again for your replies. @JoelA: This is still the same, I have already tried this. However, no matter what I try, I do not have a “Load default keys”-like option. @callpaul.eu: Windows Update is, let’s say, quite broken after I updated my dual-boot Fedora. Keeps wiping entries (ain’t they all) and I can not see the key update. However, I updated my BIOS rev from one in 2019 to 2023, the latest one, and it did not regenerate the key database.
I actually just want Secure Boot to stop MS complaining on every update and blocking it, updated from W10 a while ago and am surprised how AI slopped it is now.
And MS then goes and sends a CMOS reset after every reboot, which enables Secure Boot, but that doesn’t work due to the missing keys… I don’t know how this will end, but many thanks for your replies.
The reason for that used to be that Win updates can overwrite grub if it is on the same drive as Win. Is that still the case?
It would be possible to put Win and Linux on the same drive, and write grub somewhere else? Has anyone tried that?
Back in 2019 when I started to explore and test Linux I had both Win and Linux on the same HDD. I do not remember having problems with that configuration. I may have dual booted for a couple years or more as I started using Linux and using Win less.
Win updates are automatically done, so yes Win was updated many times during that period.
Maybe I was one of the lucky ones that did not have problems.
Normally it does not touch the grub or boot with updates only time it may happen if you go from 8 to 10 or 11
The second Tuesday security patches just fix issues and add bloatware making the system slower and bigger, microsoft programmers never tidying up behind themselves