| Previous | Next |
| TPM_E_PCP_KEY_NOT_AIK | TPM_E_LOCKED_OUT |
TPM_E_KEY_NOT_SIGNING_KEY
TPM_E_KEY_NOT_SIGNING_KEY means the selected TPM-backed key does not have signing capability, but a signing operation or attestation flow was requested.
What to check for TPM_E_KEY_NOT_SIGNING_KEY
- Verify the key algorithm and usage properties at creation time.
- Use the correct TPM-backed signing key or create a separate one with the permitted signing usage.
- Do not treat encryption or storage keys as interchangeable with signing keys.
Microsoft: CNG key storage providers
Microsoft: TPM key attestation
Microsoft: TPM and PCP error codes
Diagnostic discriminator: Inspect the selected key attributes and usage flags. This result means the key lacks signing capability, even if the key is otherwise valid and accessible.
Looking for a different code? Search another status or error code.