| Previous | Next |
| TPM_E_BAD_MIGRATION | TPM_E_BAD_DATASIZE |
TPM_E_BAD_SCHEME
Read the result in context
TPM_E_BAD_SCHEME (0x8028002A) belongs to TPM 1.2 command processing. This result means the selected signature or encryption scheme is not valid for the key and TPM 1.2 command combination.
Keep the result value 0x8028002A attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.
Fields worth decoding
- Producer: the TPM 1.2 command decoder and state machine.
- Rejected invariant: the selected signature or encryption scheme is not valid for the key and TPM 1.2 command combination.
- What to capture: algorithm ID, encScheme, sigScheme, key usage, command ordinal, key size, and the scheme list assumed by the calling library.
- Safe comparison: query capabilities and retry with one scheme explicitly supported for the same key type and operation.
Controlled comparison
Build the minimal case around the original command contract. Use a disposable object when the request can write NV data, advance a counter, change authorization state or consume a lock transition. The comparison is valid only when the caller, TPM generation and security policy remain the same.
| Question | Evidence |
|---|---|
| What exact state was rejected? | the selected signature or encryption scheme is not valid for the key and TPM 1.2 command combination |
| Which layer owns the result? | The TPM 1.2 command decoder and state machine. |
| What must be correlated? | algorithm ID, encScheme, sigScheme, key usage, command ordinal, key size, and the scheme list assumed by the calling library |
| Controlled comparison | query capabilities and retry with one scheme explicitly supported for the same key type and operation |
Adjacent failures
| Constant | Meaning |
|---|---|
TPM_E_BAD_DATASIZE | The size of the data (or blob) parameter is bad or inconsistent with the referenced key. |
TPM_E_BAD_KEY_PROPERTY | The key properties in TPM_KEY_PARMs are not supported by this TPM. |
TPM_E_BAD_MODE | A mode parameter is bad, such as capArea or subCapArea for TPM_GetCapability, phsicalPresence parameter for TPM_PhysicalPresence, or migrationType for TPM_CreateMigrationBlob. |
The codes above may appear in the same workflow, but they are not aliases. TPM_E_ENCRYPT_ERROR or TPM_E_DECRYPT_ERROR occurs during the cryptographic operation; this code rejects scheme selection.
Repair without destroying evidence
Negotiate or create a key with a compatible scheme rather than changing padding after a failed command. Do not clear ownership, delete keys or reset PCR-related state merely to see whether the message disappears; those actions can destroy the evidence and protected material while leaving serialization or command-order defects unchanged.
Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.
Source material
Looking for a different code? Search another status or error code.