What does HRESULT 0x80280030 (TPM_E_AUDITFAIL_UNSUCCESSFUL) mean?

 
Previous Next
TPM_E_NO_WRAP_TRANSPORT TPM_E_AUDITFAIL_SUCCESSFUL

TPM_E_AUDITFAIL_UNSUCCESSFUL

Which layer owns this HRESULT

TPM_E_AUDITFAIL_UNSUCCESSFUL means audit-record construction failed while the audited TPM 1.2 command was itself returning a failure.

Diagnostic record

QuestionEvidence
What exact state was rejected?audit-record construction failed while the audited TPM 1.2 command was itself returning a failure
Which layer owns the result?The TPM 1.2 command decoder and state machine.
What must be correlated?command ordinal, audit selection state, input and output digests, audit counter, command failure code, and the response bytes before wrapper translation
Controlled comparisonrun a harmless audited command to determine whether audit state is generally usable, then reproduce the original command separately

Record the original command or API call before retry logic for this result mutates its nonces, handles, buffers or state. Also retain the full HRESULT as 0x80280030; signed decimal logging can obscure the TPM/TBS facility and make searches less precise.

How to verify the distinction

  1. Establish the baseline with the same device, Windows build, account and TPM generation.
  2. Perform one narrow experiment: run a harmless audited command to determine whether audit state is generally usable, then reproduce the original command separately.
  3. Compare raw inputs and the first response, not only the final application dialog.
  4. Stop after the first changed result; if a later error replaces this HRESULT, this condition was passed even if the whole workflow still fails.

Common false equivalences

ResultDifferent diagnostic question
TPM_E_AUDITFAIL_SUCCESSFULTPM audit construction failed and the underlying command was returning success.
TPM_E_NO_WRAP_TRANSPORTThe TPM does not allow for wrapped transport sessions.
TPM_E_NOTRESETABLEAttempt to reset a PCR register that does not have the resettable attribute.

The key distinction is that TPM_E_AUDITFAIL_SUCCESSFUL means the command operation succeeded even though audit construction failed.

What a real fix looks like

To correct this, repair the audit chain or firmware issue while retaining the underlying command failure as an independent cause. Do not clear ownership, delete keys or reset PCR-related state merely to see whether the message disappears; those actions can destroy the evidence and protected material while leaving serialization or command-order defects unchanged.

Technical references


Looking for a different code? Search another status or error code.