What does HRESULT 0x80280042 (TPM_E_BAD_ATTRIBUTES) mean?

 
Previous Next
TPM_E_WRITE_LOCKED TPM_E_INVALID_STRUCTURE

TPM_E_BAD_ATTRIBUTES

Read the result in context

TPM_E_BAD_ATTRIBUTES (0x80280042) belongs to TPM 1.2 nonvolatile-storage policy. This result means the combination of TPM 1.2 NV attributes is internally contradictory or forbidden.

The first producer to identify is the TPM 1.2 NV permission and lifecycle checks. TPM 1.2 NV indices combine permissions, authorization mode, locality masks and lock semantics. Two indices of the same size can behave differently because those attributes were fixed when each index was defined.

Keep the result value 0x80280042 attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.

Fields worth decoding

  • Producer: the TPM 1.2 NV permission and lifecycle checks.
  • Rejected invariant: the combination of TPM 1.2 NV attributes is internally contradictory or forbidden.
  • What to capture: all permission bits, locality masks, index type, authorization flags, size, and the define-space structure before serialization.
  • Safe comparison: start from a minimal accepted NV definition and add one attribute at a time until the conflicting pair is isolated.

Controlled comparison

QuestionEvidence
What exact state was rejected?the combination of TPM 1.2 NV attributes is internally contradictory or forbidden
Which layer owns the result?The TPM 1.2 NV permission and lifecycle checks.
What must be correlated?all permission bits, locality masks, index type, authorization flags, size, and the define-space structure before serialization
Controlled comparisonstart from a minimal accepted NV definition and add one attribute at a time until the conflicting pair is isolated

Adjacent failures

ConstantMeaning
TPM_E_NOT_FULLWRITEThe write is not a complete write of the area.
TPM_E_WRITE_LOCKEDThe NV area has already been written to.
TPM_E_MAXNVWRITESThe maximum number of NV writes without an owner has been exceeded.

The codes above may appear in the same workflow, but they are not aliases. TPM_E_PER_NOWRITE focuses on missing write protection, while this code covers broader attribute conflicts.

Repair without destroying evidence

Redesign the index policy with a supported attribute combination; do not patch only the returned hresult. Do not undefine a production NV index until its public attributes and authorization policy have been recorded. NV policy is established at definition time, and destructive recreation can remove counters, certificates or provisioning state.

Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.

Source material


Looking for a different code? Search another status or error code.