| Previous | Next |
| CERTSRV_E_WEAK_SIGNATURE_OR_KEY | CERTSRV_E_ENCRYPTION_CERT_REQUIRED |
CERTSRV_E_KEY_ATTESTATION_NOT_SUPPORTED
CERTSRV_E_KEY_ATTESTATION_NOT_SUPPORTED The client could not create an attested key because the TPM, smart-card/KSP, cryptographic provider, or platform configuration does not meet the hardware requirements for key attestation.
What to check
- Confirm that the selected template requires key attestation and that the device/provider is supported for that template type.
- Verify TPM readiness, firmware state, and the selected key storage provider before changing certificate-template policy.
- For a non-attestation use case, use a separate template without attestation rather than weakening the security intent of an attested template.
Microsoft: TPM Key Attestation
Microsoft: Active Directory Certificate Services overview
Microsoft: Certificate template concepts
Looking for a different code? Search another status or error code.