What does HRESULT 0x8028005E (TPM_E_MA_SOURCE) mean?

 
Previous Next
TPM_E_MA_DESTINATION TPM_E_MA_AUTHORITY

TPM_E_MA_SOURCE

Which layer owns this HRESULT

TPM_E_MA_SOURCE means the source identity or source binding in the certified-migration workflow is inconsistent.

The first producer to identify is the certified-migration, key-policy or EK administrative checkpoint. TPM 1.2 migration policy is encoded when a key is created and reinforced by signed authority tickets and source/destination bindings. Migration errors therefore require the original binary artifacts and key attributes, not only the user-visible key name.

Keep the result value 0x8028005E attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.

Diagnostic record

  • Producer: the certified-migration, key-policy or EK administrative checkpoint.
  • Rejected invariant: the source identity or source binding in the certified-migration workflow is inconsistent.
  • What to capture: source key and digest, original CMK attributes, authority ticket, destination data, parent relationship, and migration command.
  • Safe comparison: reconstruct the migration package from the original source key and compare all source identifiers.

How to verify the distinction

QuestionEvidence
What exact state was rejected?the source identity or source binding in the certified-migration workflow is inconsistent
Which layer owns the result?The certified-migration, key-policy or EK administrative checkpoint.
What must be correlated?source key and digest, original CMK attributes, authority ticket, destination data, parent relationship, and migration command
Controlled comparisonreconstruct the migration package from the original source key and compare all source identifiers

Common false equivalences

ConstantMeaning
TPM_E_MA_AUTHORITYIncorrect migration authority.
TPM_E_MA_DESTINATIONMigration destination not authenticated.
TPM_E_PERMANENTEKAttempt to revoke the EK and the EK is not revocable.

The codes above may appear in the same workflow, but they are not aliases. TPM_E_MA_DESTINATION concerns authentication of the target rather than the source.

What a real fix looks like

Use the actual originating cmk and issue a new authority-approved migration package. Do not edit a signed ticket, migration blob or opaque private-key structure. Binary normalization, JSON conversion or base64 line handling can invalidate the authority and integrity relationships.

Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.

Source material


Looking for a different code? Search another status or error code.