| Previous | Next |
| TPM_E_MA_DESTINATION | TPM_E_MA_AUTHORITY |
TPM_E_MA_SOURCE
Which layer owns this HRESULT
TPM_E_MA_SOURCE means the source identity or source binding in the certified-migration workflow is inconsistent.
The first producer to identify is the certified-migration, key-policy or EK administrative checkpoint. TPM 1.2 migration policy is encoded when a key is created and reinforced by signed authority tickets and source/destination bindings. Migration errors therefore require the original binary artifacts and key attributes, not only the user-visible key name.
Keep the result value 0x8028005E attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.
Diagnostic record
- Producer: the certified-migration, key-policy or EK administrative checkpoint.
- Rejected invariant: the source identity or source binding in the certified-migration workflow is inconsistent.
- What to capture: source key and digest, original CMK attributes, authority ticket, destination data, parent relationship, and migration command.
- Safe comparison: reconstruct the migration package from the original source key and compare all source identifiers.
How to verify the distinction
| Question | Evidence |
|---|---|
| What exact state was rejected? | the source identity or source binding in the certified-migration workflow is inconsistent |
| Which layer owns the result? | The certified-migration, key-policy or EK administrative checkpoint. |
| What must be correlated? | source key and digest, original CMK attributes, authority ticket, destination data, parent relationship, and migration command |
| Controlled comparison | reconstruct the migration package from the original source key and compare all source identifiers |
Common false equivalences
| Constant | Meaning |
|---|---|
TPM_E_MA_AUTHORITY | Incorrect migration authority. |
TPM_E_MA_DESTINATION | Migration destination not authenticated. |
TPM_E_PERMANENTEK | Attempt to revoke the EK and the EK is not revocable. |
The codes above may appear in the same workflow, but they are not aliases. TPM_E_MA_DESTINATION concerns authentication of the target rather than the source.
What a real fix looks like
Use the actual originating cmk and issue a new authority-approved migration package. Do not edit a signed ticket, migration blob or opaque private-key structure. Binary normalization, JSON conversion or base64 line handling can invalidate the authority and integrity relationships.
Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.
Source material
Looking for a different code? Search another status or error code.