What does HRESULT 0x8028005B (TPM_E_TOOMANYCONTEXTS) mean?

 
Previous Next
TPM_E_BADCONTEXT TPM_E_MA_TICKET_SIGNATURE

TPM_E_TOOMANYCONTEXTS

The protocol condition

TPM_E_TOOMANYCONTEXTS (0x8028005B) belongs to TPM 1.2 resources, delegation and contexts. This result means the TPM 1.2 device is already holding the maximum number of saved contexts for the relevant operation.

Nearest useful distinction: This value corresponds to “Too many contexts held by the TPM.” Keep that condition separate from adjacent errors that may expose the same high-level symptom.

The first producer to identify is the TPM resource, context or delegation manager, sometimes mediated by TBS virtualization. TBS can virtualize finite TPM resources, but a saved TPM context and a TBS virtual handle are not durable application IDs. Their validity depends on resource type, owning client context, TPM lifecycle and the exact save/load history.

Keep the result value 0x8028005B attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.

What to preserve before retrying

  • Producer: the TPM resource, context or delegation manager, sometimes mediated by TBS virtualization.
  • Rejected invariant: the TPM 1.2 device is already holding the maximum number of saved contexts for the relevant operation.
  • What to capture: number and type of active/saved contexts, owning processes, abandoned sessions, TBS context count, and cleanup behavior.
  • Safe comparison: close a known test context and verify that one new context can then be created.

Minimal reproduction

QuestionEvidence
What exact state was rejected?the TPM 1.2 device is already holding the maximum number of saved contexts for the relevant operation
Which layer owns the result?The TPM resource, context or delegation manager, sometimes mediated by TBS virtualization.
What must be correlated?number and type of active/saved contexts, owning processes, abandoned sessions, TBS context count, and cleanup behavior
Controlled comparisonclose a known test context and verify that one new context can then be created

Nearby codes with different meanings

ConstantMeaning
TPM_E_NOCONTEXTSPACEThere is no room in the context list for additional contexts.
TPM_E_BADCONTEXTThe context blob is invalid.
TPM_E_BAD_DELEGATEDelegation is not correct.

The codes above may appear in the same workflow, but they are not aliases. TPM_E_NOCONTEXTSPACE reports lack of room in the context list, a closely related but distinct storage boundary.

Resolution criteria

Close or flush unused contexts and redesign long-lived handle caching; do not increase application concurrency blindly. Do not persist volatile TPM or TBS handles as durable identifiers. A numeric handle can be valid only inside the creating context and lifecycle, even when its value looks unchanged after restart.

Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.

Source material


Looking for a different code? Search another status or error code.