| Previous | Next |
| TBS_E_COMMAND_CANCELED | TBS_E_TPM_NOT_FOUND |
TBS_E_BUFFER_TOO_LARGE
Classify the layer correctly
TBS_E_BUFFER_TOO_LARGE (0x8028400E) belongs to the public and internal TPM Base Services path. It indicates a public TBS input or requested output size exceeds the service’s accepted maximum.
The first producer to identify is the TBS client library, local RPC service and command scheduler before or around device execution. TBS centralizes TPM access through a local RPC service. A failure can therefore occur in the caller contract, RPC/service startup, scheduling, buffer handling or TPM submission, and each layer requires different evidence.
Incident worksheet
Preserve these this result items before changing anything:
- This result and
0x8028400E, the exact returning method or command, and the first nested status. - cbCommand, output capacity, arithmetic used to build lengths, structure nesting, command header paramSize, and TBS_IN_OUT_BUF_SIZE_MAX.
- The TPM generation, manufacturer/firmware revision, Windows build, caller identity and TBS/provider state.
- The complete opaque request artifacts, redacting authorization secrets but not rewriting structure boundaries.
A reproducible comparison
Run this focused check: submit a minimal valid command and then test the exact documented boundary size. Do not combine the test with firmware updates, TPM clearing, account changes, key recreation and policy edits in the same trial; such a result cannot isolate this boundary.
| Stage | Pass condition |
|---|---|
| a public TBS input or requested output size exceeds the service’s accepted maximum | The original command reaches the next defined state without returning it. |
| Security behavior | The result verification still uses the intended TPM, authorization, locality and policy. |
| Output integrity | The object, digest, event log or state transition produced after it validates independently. |
Related conditions often confused with this one
| Related result | Separate meaning |
|---|---|
TBS_E_ACCESS_DENIED | The caller does not have the appropriate rights to perform the requested operation. |
TBS_E_COMMAND_CANCELED | The command was canceled. |
TBSIMP_E_BUFFER_TOO_SMALL | The specified buffer was too small. |
The practical distinction is that TBS_E_INSUFFICIENT_BUFFER means a legitimate result does not fit in a smaller caller buffer.
Restore service safely
The supported direction is to validate lengths before allocation and split only at protocol-defined boundaries; do not truncate a TPM command. Do not restart or disable TBS before capturing its service and event data. Most caller-contract errors are reproducible without touching TPM ownership, firmware state or stored keys.
Technical references
- Microsoft: About TPM Base Services — source for this result.
- Microsoft: TBS return codes — source for this result.
- Microsoft: Tbsi_Context_Create — source for this result.
- Microsoft: Tbsip_Submit_Command — source for this result.
Looking for a different code? Search another status or error code.