What does HRESULT 0x8028001E (TPM_E_BADTAG) mean?

 
Previous Next
TPM_E_AUTH2FAIL TPM_E_IOERROR

TPM_E_BADTAG

What failed and what did not

TPM_E_BADTAG (0x8028001E) belongs to TPM 1.2 command processing. This result means the request header tag does not match a valid TPM 1.2 command form or its expected authorization-session count.

Keep the result value 0x8028001E attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.

Collect a useful trace

  • Producer: the TPM 1.2 command decoder and state machine.
  • Rejected invariant: the request header tag does not match a valid TPM 1.2 command form or its expected authorization-session count.
  • What to capture: the raw request header bytes, tag, paramSize, ordinal, expected auth areas, byte order, and the response header before any library translation.
  • Safe comparison: decode the command buffer independently and compare its tag with the command variant actually serialized.

Narrow experiment

Build the minimal case around the original command contract. Use a disposable object when the request can write NV data, advance a counter, change authorization state or consume a lock transition. The comparison is valid only when the caller, TPM generation and security policy remain the same.

QuestionEvidence
What exact state was rejected?the request header tag does not match a valid TPM 1.2 command form or its expected authorization-session count
Which layer owns the result?The TPM 1.2 command decoder and state machine.
What must be correlated?the raw request header bytes, tag, paramSize, ordinal, expected auth areas, byte order, and the response header before any library translation
Controlled comparisondecode the command buffer independently and compare its tag with the command variant actually serialized

Similar-looking outcomes

ConstantMeaning
TPM_E_IOERRORAn IO error occurred transmitting information to the TPM.
TPM_E_SHA_ERRORThe calculation is unable to proceed because the existing SHA-1 thread has already encountered an error.
TPM_E_ENCRYPT_ERRORThe encryption process had a problem.

The codes above may appear in the same workflow, but they are not aliases. TPM_E_BAD_DATASIZE concerns a body or blob length after framing; it rejects the header form itself.

Operational response

Construct the header from the tpm structure definition and make the tag agree with the number and kind of authorization sessions. Do not clear ownership, delete keys or reset PCR-related state merely to see whether the message disappears; those actions can destroy the evidence and protected material while leaving serialization or command-order defects unchanged.

Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.

Source material


Looking for a different code? Search another status or error code.