What does HRESULT 0x80280034 (TPM_E_BAD_TYPE) mean?

 
Previous Next
TPM_E_NOTLOCAL TPM_E_INVALID_RESOURCE

TPM_E_BAD_TYPE

The decisive TPM checkpoint

TPM_E_BAD_TYPE (0x80280034) belongs to TPM 1.2 command processing. The base What Is page already shows the short Windows message; the additional diagnostic value is that this result marks an identity-related blob carries the wrong TPM 1.2 structure type or tag for the command consuming it.

The first producer to identify for this HRESULT is the TPM 1.2 command decoder and state machine. TPM 1.2 is a command/response device with strict binary structures and stateful resources. Windows may present the device response as an HRESULT, but the diagnostic meaning still belongs to the command field, key, session, PCR, NV index or lifecycle check named by the TPM specification.

Before changing the platform

Preserve these this result items before changing anything:

  • This result and 0x80280034, the exact returning method or command, and the first nested status.
  • outer structure tag, version, length, identity key type, credential or challenge type, and the serialization source.
  • The TPM generation, manufacturer/firmware revision, Windows build, caller identity and TBS/provider state for this HRESULT.
  • The complete opaque request artifacts, redacting authorization secrets but not rewriting structure boundaries.

Test the contract

Run this focused check: decode the blob against the exact TPM structure expected by the command and compare with a newly generated test blob. Do not combine the result test with firmware updates, TPM clearing, account changes, key recreation and policy edits in the same trial; such a result cannot isolate this boundary.

CheckpointPass condition
an identity-related blob carries the wrong TPM 1.2 structure type or tag for the command consuming itThe original this result command reaches the next defined state without returning it.
Security behaviorThe result verification still uses the intended TPM, authorization, locality and policy.
Output integrityThe object, digest, event log or state transition produced after it validates independently.

Why another code is not equivalent

Related resultSeparate meaning
TPM_E_NOTFIPSThe TPM is attempting to execute a command only available when in FIPS mode — a separate checkpoint when compared with it.
TPM_E_NOTLOCALAttempt to reset a PCR register that requires locality and locality modifier not part of command transport — a separate checkpoint when compared with it.
TPM_E_NOTRESETABLEAttempt to reset a PCR register that does not have the resettable attribute — a separate checkpoint when compared with it.

The practical distinction is that TPM_E_INVALID_STRUCTURE is a broader tag/version inconsistency; this code is tied to the identity blob type.

Evidence of success

The supported direction is to regenerate the blob with the correct structure definition and keep versioned identity formats separate. Do not clear ownership, delete keys or reset PCR-related state merely to see whether the message disappears; those actions can destroy the evidence and protected material while leaving serialization or command-order defects unchanged.

If the same bytes still return it after the documented preconditions are satisfied, retain this code-specific trace for the platform vendor or Windows component owner rather than erasing state.

Technical references


Looking for a different code? Search another status or error code.