| Previous | Next |
| TPM_E_BAD_SCHEME | TPM_E_BAD_MODE |
TPM_E_BAD_DATASIZE
Which layer owns this HRESULT
TPM_E_BAD_DATASIZE (0x8028002B) belongs to TPM 1.2 command processing. This result means a data-size mismatch: a TPM 1.2 data or blob length is inconsistent with the command, key, scheme or enclosing structure.
Keep the result value 0x8028002B attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.
Diagnostic record
- Producer: the TPM 1.2 command decoder and state machine.
- Rejected invariant: a TPM 1.2 data or blob length is inconsistent with the command, key, scheme or enclosing structure.
- What to capture: declared and actual lengths at every layer, paramSize, key modulus size, encrypted blob size, structure tags, and any base64 or network conversion.
- Safe comparison: compare a byte-for-byte command decode with the specification and test the nearest valid boundary size.
How to verify the distinction
Build the minimal case around the original command contract. Use a disposable object when the request can write NV data, advance a counter, change authorization state or consume a lock transition. The comparison is valid only when the caller, TPM generation and security policy remain the same.
| Question | Evidence |
|---|---|
| What exact state was rejected? | a TPM 1.2 data or blob length is inconsistent with the command, key, scheme or enclosing structure |
| Which layer owns the result? | The TPM 1.2 command decoder and state machine. |
| What must be correlated? | declared and actual lengths at every layer, paramSize, key modulus size, encrypted blob size, structure tags, and any base64 or network conversion |
| Controlled comparison | compare a byte-for-byte command decode with the specification and test the nearest valid boundary size |
Common false equivalences
| Constant | Meaning |
|---|---|
TPM_E_BAD_MODE | A mode parameter is bad, such as capArea or subCapArea for TPM_GetCapability, phsicalPresence parameter for TPM_PhysicalPresence, or migrationType for TPM_CreateMigrationBlob. |
TPM_E_BAD_SCHEME | The signature or encryption scheme for this key is incorrect or not permitted in this situation. |
TPM_E_BAD_PRESENCE | Either the physicalPresence or physicalPresenceLock bits have the wrong value. |
The codes above may appear in the same workflow, but they are not aliases. TPM_E_BADTAG rejects header type, while it reaches a length relationship in the body or referenced object.
What a real fix looks like
Fix serialization and preserve binary data exactly; increasing an output buffer cannot repair a malformed length inside the request. Do not clear ownership, delete keys or reset PCR-related state merely to see whether the message disappears; those actions can destroy the evidence and protected material while leaving serialization or command-order defects unchanged.
Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.
Source material
Looking for a different code? Search another status or error code.