Loading...
Loading...
By default, HPE Compute XD690 systems do not have the Platform Key (PK), Key Exchange Key database (KEK), authorized signature database (DB), or forbidden signature database (DBX) populated. Customers using UEFI Secure Boot must establish trust for the operating-system bootloader. When HPE-signed drivers or components are used, customers must enroll the applicable HPE DB certificate and enroll the HPE KEK only when the approved HPE procedure or component documentation requires it. Use this advisory to configure the required trust databases and verify the resulting Secure Boot configuration.Related XD690 Customer AdvisoriesAdvisory Comparison:Advisory:HPE Compute XD690 BIOS Update Resets Custom BIOS Parameters and Boot OrderCustomer Scenario:BIOS updates can reset custom BIOS parameters and boot order.Direct Link:HPE Support Site LinkAdvisory:HPE Compute XD690 BIOS Update Secure Boot Key Backup and Restore GuidanceCustomer Scenario:Secure Boot keys must be backed up or restored following a BIOS update.Direct Link:HPE Support Site LinkAdvisory:HPE Compute XD690 - HPE-Signed Drivers May Fail to Load When HPE Secure Boot Certificates Are Not EnrolledCustomer Scenario: UEFI Secure Boot is enabled and the operating system boots successfully, but an HPE-signed driver or component may fail to load because the applicable HPE Secure Boot certificate is not enrolled in the UEFI authorized signature database.Direct Link:HPE Support Site LinkAdvisory:HPE Compute XD690 UEFI Secure Boot GuidanceCustomer Scenario:Explains how to establish operating-system boot trust and enroll the HPE DB certificate required for HPE-signed components, with links to the separate BIOS-update advisories.Direct Link: This Advisory
For Secure Boot requirements, BIOS navigation, and certificate-management information, refer to the HPE Compute XD690 System User Guide, HPE Compute XD690 BIOS Setup User Guide, HPE Secure Boot Customization Guide, and the HPE Linux Software Delivery Repository resources listed in References. Before performing a BIOS update, review theHPE Compute XD690 BIOS Update Secure Boot Key Backup and Restore Guidancefor the approved instructions to preserve and restore enrolled Secure Boot keys and certificates.This advisory applies to HPE Compute XD690 systems configured to use UEFI Secure Boot. The required certificates depend on what the system must validate. Operating-system boot trust requires the certificates specified by the supported operating system or the customer’s approved signing and enrollment process. HPE-signed component trust requires the applicable HPE DB certificate; enroll the HPE KEK only when the approved HPE procedure or component documentation specifically requires it.Operating-system boot trust: Enroll the certificates required by the supported operating system, or use the customer’s approved signing and enrollment process.HPE-signed component trust: Enroll the applicable HPE DB certificate when HPE-signed drivers or components are used. Enroll the HPE KEK only when the approved HPE procedure or component documentation specifically requires it.Related BIOS-update guidance: Before updating the BIOS, follow the related XD690 advisories for preserving custom BIOS settings and Secure Boot keys.If the required operating-system certificates are not enrolled, the operating-system bootloader might not be trusted and the system may fail to boot with Secure Boot enabled. If the required HPE DB certificate is not enrolled, the operating system might boot while an HPE-signed driver or component does not load. For this condition, seeHPE Compute XD690 - HPE-Signed Drivers May Fail to Load When HPE Secure Boot Certificates Are Not Enrolled. For symptoms following a BIOS update, see the related XD690 advisories listed above.The XD690 UEFI Secure Boot trust database might not include the certificates required by the customer’s operating system or HPE-signed components. Customers must enroll the appropriate certificates for their configuration. The condition may also occur after system maintenance activities, such as a BIOS update. Current HPE Compute XD690 BIOS revisions may remove previously enrolled Secure Boot certificates from the UEFI Secure Boot trust database during the update process. When this occurs, the required Secure Boot certificates must be restored. Refer to theHPE Compute XD690 BIOS Update Secure Boot Key Backup and Restore Guidanceto verify and restore the required certificates after a BIOS update.
Use only certificates obtained from the operating-system provider, the customer’s approved signing process, or an approved HPE source. Do not use Reset to Setup Mode or clear the Secure Boot key databases as part of this procedure.Configure Secure Boot TrustReview the platform instructions. Use the HPE Compute XD690 System User Guide and HPE Compute XD690 BIOS Setup User Guide for Secure Boot requirements and key-management instructions. Before performing a BIOS update, also review theHPE Compute XD690 BIOS Update Secure Boot Key Backup and Restore Guidancefor instructions to preserve and restore enrolled Secure Boot keys and certificates.Establish operating-system boot trust. Enroll the certificates required by the supported operating system, including applicable Microsoft UEFI certificates when the Linux boot chain depends on Microsoft-signed components, or follow the customer’s approved process for generating, signing, and enrolling custom keys. These certificates establish trust for the operating-system bootloader; they do not replace the HPE certificates required for HPE-signed drivers or components.Add HPE certificates when required. If the configuration uses HPE-signed drivers or components, obtain the approved HPE DB certificate from the HPE Linux Software Delivery Repository and append it to DB without removing existing trust entries. Enroll the HPE KEK only if the approved HPE procedure or component documentation specifically requires it. Do not replace or reenroll PK, KEK, or DB solely to resolve an HPE-signed driver-loading issue unless the approved procedure explicitly directs that action.Save and reset the system. After enrollment, save the BIOS settings and complete the required reset.Verify Secure Boot. Re-enter BIOS Setup and confirm that Secure Boot is enabled and active and that the expected PK, KEK, DB, and DBX entries are present.Validate the workload. Boot the supported operating system, install or load the required HPE-signed drivers, and confirm that the associated network adapters are detected and operational. Reboot the system and verify that Secure Boot remains enabled and that the drivers continue to load without signature-verification errors.Before updating the BIOS, follow the HPE Compute XD690 BIOS Update Secure Boot Key Backup and Restore Guidance listed in References. That advisory provides the approved instructions for preserving and restoring enrolled Secure Boot keys.After a BIOS update, follow the HPE Compute XD690 BIOS Update Secure Boot Key Backup and Restore Guidance to verify and, when required, restore the enrolled Secure Boot keys. After restoration, confirm that Secure Boot is active and validate the operating-system bootloader and required signed components.If the system does not boot, Secure Boot is not active, or a signed driver does not load after enrollment, do not clear the Secure Boot databases. Follow the HPE Compute XD690 BIOS Update Secure Boot Key Backup and Restore Guidance when the issue occurs after BIOS maintenance. Before contacting HPE Support, collect the BIOS revision, operating-system version, Secure Boot state, enrolled-key inventory, affected driver or component version, and relevant signature-verification errors.Internal validation on HPE Compute XD690 systems confirmed that RHEL 9.6 could install and boot successfully with UEFI Secure Boot enabled while HPE-signed OFED drivers failed to load on systems that did not contain the applicable HPE Secure Boot trust certificate. Observed symptoms included driver initialization failures, unavailable network interfaces, and loss of expected network functionality.Comparison testing showed that successful systems contained the applicable HPE certificate in the UEFI authorized signature database (DB), while affected systems did not. After the required HPE DB certificate was enrolled, validation confirmed that Secure Boot remained enabled, HPE-signed drivers loaded successfully, network adapters were detected and operational, and functionality was maintained after reboot.The validated workflow included confirming network-adapter detection, establishing operating-system boot trust, appending the applicable HPE DB certificate without removing existing trust entries, and enrolling the HPE KEK only when required by the approved procedure or component documentation. Validation then confirmed successful operating-system installation, HPE-signed driver loading, network-adapter operation, and Secure Boot status following reboot. See Configure Secure Boot Trust for the detailed customer procedure.These results confirm that successful operating-system installation does not by itself verify trust for HPE-signed components. A system can boot successfully with Secure Boot enabled but still prevent HPE-signed drivers from loading when the applicable HPE DB certificate is not enrolled.ReferencesHPE Compute XD690 System User GuideHPE Compute XD690 product manuals, select the BIOS Setup User Guide.HPE KEK certificate repositoryHPE DB certificate repositoryHPE Compute XD690 BIOS Update Secure Boot Key Backup and Restore GuidanceHPE Compute XD690 - HPE-Signed Drivers May Fail to Load When HPE Secure Boot Certificates are not enrolled
Operating Systems Affected:Not Applicable
Click on a version to see all relevant bugs
Hewlett Packard Enterprise Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.