Has anyone successfully booted IGEL OS, Ubuntu, or another Microsoft-signed Linux distribution on an HP t640 while Secure Boot is enabled? When the firmware is set to use the HP keys, I receive a Secure Boot Violation, and my BIOS does not show an option named "Allow Microsoft 3rd Party UEFI CA." If you have this working, which BIOS version and Secure Boot settings are you using? I'm especially interested in a method that can be automated across many devices rather than configured manually.
3 Answers
One possible approach is to create and enroll custom Secure Boot keys in the BIOS. For some systems, the bootloader and additional binaries also need to be signed with keys that are trusted by the firmware.
For a larger deployment, you could generate a custom Secure Boot certificate with Linux and OpenSSL, then use a PowerShell script to enroll it on a test t640. Once that works, the same script could be pushed to the rest of the fleet before installing the operating system through PXE. A custom WinPE image is another option if remote PowerShell deployment is not available.
The t640 can run Windows 11 with Secure Boot, but that does not necessarily confirm that third-party Linux bootloaders will be accepted. The important details to compare are the exact BIOS revision, whether the default HP keys remain installed, and whether the distribution’s bootloader is signed by a certificate trusted by the firmware.
I’m specifically trying to verify non-Windows booting. Testing an Ubuntu USB with Secure Boot enabled, along with the BIOS version, would help determine whether this is a signing issue or a firmware limitation.

That sounds more practical for a fleet than configuring every machine by hand. I was hoping there might be a firmware setting equivalent to the Microsoft third-party UEFI CA, but custom key enrollment may be the fallback.