[Guide] Howto Unlock/Flash an Insyde H2O UEFI BIOS

In the matter of the topic I only uploaded makecert.exe, pvk2pfx.exe, MakeKeyFirst.bat, MakeKeySecond.bat. You have a limitation of 50MB per download on Chomikuj file-sharing.

A new certificate can be created with “makecert.exe” tool. There was no need for poster to publish the QA cert as it is being generated with random seed by default.

We still missing private keys from the manuf. It is necessary to have those files to generate a correct private key – public key pair, because the priv. key is that seed we use to generate certificate. So, the whole topic is a big nonsense itself.

So to say, the part about certificates belongs to “external” protection of flash memory. It is only valid untill the BIOS image is flashed by the genuine flashing tool. But there is also such thing as internal sanity, when already flashed BIOS performs the integrity check at some point of initialization.
Devices I know have this technology: Lenovo B50-30, Acer Swift 3 SF314, Xiaomi Redmi G 2021, most of HP Notebooks…

Yours might be one of those.

Ah, sure… Just got to know your device is Lenovo B40-30. It’s unfortunate, but I have no solution. I’m barely understanding how encryption things are actually work.

1 Like