What does HRESULT 0x80280041 (TPM_E_WRITE_LOCKED) mean?

 
Previous Next
TPM_E_FAMILYCOUNT TPM_E_BAD_ATTRIBUTES

TPM_E_WRITE_LOCKED

Interpret the condition first

TPM_E_WRITE_LOCKED (0x80280041) belongs to TPM 1.2 nonvolatile-storage policy. This result means a write-locked state: a TPM 1.2 NV index with one-time or lock-on-write semantics has already consumed the permitted write state.

The first producer to identify is the TPM 1.2 NV permission and lifecycle checks. TPM 1.2 NV indices combine permissions, authorization mode, locality masks and lock semantics. Two indices of the same size can behave differently because those attributes were fixed when each index was defined.

Keep the result value 0x80280041 attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.

Build the command transcript

  • Producer: the TPM 1.2 NV permission and lifecycle checks.
  • Rejected invariant: a TPM 1.2 NV index with one-time or lock-on-write semantics has already consumed the permitted write state.
  • What to capture: NV attributes, prior successful writes, writeAll requirement, lock bits, boot cycle, offset and length, and audit trail.
  • Safe comparison: reproduce with a newly defined disposable index and perform the first and second writes separately.

Test one hypothesis

QuestionEvidence
What exact state was rejected?a TPM 1.2 NV index with one-time or lock-on-write semantics has already consumed the permitted write state
Which layer owns the result?The TPM 1.2 NV permission and lifecycle checks.
What must be correlated?NV attributes, prior successful writes, writeAll requirement, lock bits, boot cycle, offset and length, and audit trail
Controlled comparisonreproduce with a newly defined disposable index and perform the first and second writes separately

Do not merge these conditions

ConstantMeaning
TPM_E_BAD_ATTRIBUTESThe NV area attributes conflict.
TPM_E_FAMILYCOUNTThe family count value does not match.
TPM_E_NOT_FULLWRITEThe write is not a complete write of the area.

The codes above may appear in the same workflow, but they are not aliases. TPM_E_AREA_LOCKED may follow an explicit lock; this code often distinguishes a write-once lifecycle already consumed.

A safe recovery path

Treat the existing index as immutable for its defined lifetime and provision a replacement index through a controlled migration. Do not undefine a production NV index until its public attributes and authorization policy have been recorded. NV policy is established at definition time, and destructive recreation can remove counters, certificates or provisioning state.

Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.

Source material


Looking for a different code? Search another status or error code.