What does HRESULT 0x80094017 (CERTSRV_E_KEY_ATTESTATION_NOT_SUPPORTED) mean?

 
Previous Next
CERTSRV_E_WEAK_SIGNATURE_OR_KEY CERTSRV_E_ENCRYPTION_CERT_REQUIRED

CERTSRV_E_KEY_ATTESTATION_NOT_SUPPORTED

CERTSRV_E_KEY_ATTESTATION_NOT_SUPPORTED The client could not create an attested key because the TPM, smart-card/KSP, cryptographic provider, or platform configuration does not meet the hardware requirements for key attestation.

What to check

  • Confirm that the selected template requires key attestation and that the device/provider is supported for that template type.
  • Verify TPM readiness, firmware state, and the selected key storage provider before changing certificate-template policy.
  • For a non-attestation use case, use a separate template without attestation rather than weakening the security intent of an attested template.

Microsoft: TPM Key Attestation

Microsoft: Active Directory Certificate Services overview

Microsoft: Certificate template concepts


Looking for a different code? Search another status or error code.