What does HRESULT 0x8028001B (TPM_E_SHA_ERROR) mean?

 
Previous Next
TPM_E_SHA_THREAD TPM_E_FAILEDSELFTEST

TPM_E_SHA_ERROR

Which layer owns this HRESULT

TPM_E_SHA_ERROR (0x8028001B) belongs to TPM 1.2 command processing. This result means an existing TPM 1.2 SHA-1 thread has become unusable, so later update or completion work cannot continue.

The first producer to identify is the TPM 1.2 command decoder and state machine. TPM 1.2 is a command/response device with strict binary structures and stateful resources. Windows may present the device response as an HRESULT, but the diagnostic meaning still belongs to the command field, key, session, PCR, NV index or lifecycle check named by the TPM specification.

Diagnostic record

Preserve these items before changing anything:

  • This result and 0x8028001B, the exact returning method or command, and the first nested status.
  • the first failing chunk, total byte count promised at start, update sizes, completion command, and whether the device slept or the context was closed.
  • Record the TPM generation, manufacturer/firmware revision, Windows build, caller identity, and TBS/provider state.
  • The complete opaque request artifacts, redacting authorization secrets but not rewriting structure boundaries.

How to verify the distinction

Run this focused check: repeat with the same data in a fresh SHA thread and fixed chunk boundaries, stopping at the first command that changes the state. Do not combine the test with firmware updates, TPM clearing, account changes, key recreation and policy edits in the same trial; such a result cannot isolate this boundary.

StagePass condition
an existing TPM 1.2 SHA-1 thread has become unusable, so later update or completion work cannot continueThe original command reaches the next defined state without returning it.
Security behaviorVerification still uses the intended TPM, authorization, locality and policy.
Output integrityThe object, digest, event log or state transition produced after it validates independently.

Common false equivalences

Related resultSeparate meaning
TPM_E_BADTAGThe tag value sent to for a command is invalid.
TPM_E_SHA_THREADThere is no existing SHA-1 thread.
TPM_E_IOERRORAn IO error occurred transmitting information to the TPM.

The practical distinction is that TPM_E_SHA_THREAD indicates that no thread exists; it indicates a thread whose prior operation already failed.

What a real fix looks like

The supported direction is to discard the failed thread and correct the earlier length, sequencing, or transport problem before starting a new hash. Do not clear ownership, delete keys or reset PCR-related state merely to see whether the message disappears; those actions can destroy the evidence and protected material while leaving serialization or command-order defects unchanged.

Technical references


Looking for a different code? Search another status or error code.