| Previous | Next |
| NS_E_DRM_UNABLE_TO_GET_DEVICE_CERT | NS_E_DRM_UNABLE_TO_SET_SECURE_CLOCK |
NS_E_DRM_UNABLE_TO_GET_SECURE_CLOCK
Meaning beyond the player message
The symbolic result NS_E_DRM_UNABLE_TO_GET_SECURE_CLOCK narrows 0xC00D2773 to portable-device certificate, secure clock and transfer policy. In practical terms, the DRM client cannot read the device or local secure clock; the producing layer is the device-facing path that authenticates a WMDRM-capable device, obtains its certificate and secure clock, evaluates transfer policy, and records metering or registration state.
Record device capability, clock status and last successful initialization.
Which component owns the failure
Do not flatten this result into a generic DRM error. A device can be reachable as storage while still failing WMDRM authentication, secure-clock or policy requirements. The second relevant rule is that time-bound and subscription licenses may require a trusted device clock; changing the host clock does not repair a device clock that was never obtained or set.
How to prove the condition
- Prove the boundary by ensuring you can record device capability, clock status and last successful initialization.
- After you initialize or repair the secure-clock provider before evaluating time-bound rights, verify both the requested right and the final store/device state.
Diagnostic inputs that separate the causes
- Code-specific proof: record device capability, clock status and last successful initialization.
- Protected identity: secure clock value, source and last successful update.
- Operation state: requested transfer/burn action and license restriction.
- Persistence or transport: device activation, registration and metering result.
- Security context: device model, firmware and WMDRM capability.
- Correlation point: device certificate chain and serial identity.
Do not merge these HRESULTs
| Result | Different condition |
|---|---|
NS_E_DRM_UNABLE_TO_GET_DEVICE_CERT | The client cannot retrieve or validate the target device certificate. |
NS_E_DRM_UNABLE_TO_SET_SECURE_CLOCK | The DRM client cannot commit secure-clock data to the device. |
NS_E_DRM_TRACK_EXCEEDED_TRACKBURN_RESTRICTION | The track has exhausted its overall burn count in the Windows Media DRM client |
What a supported fix should change
Resolve the underlying condition directly: initialize or repair the secure-clock provider before evaluating time-bound rights. A player reinstall, reboot or new license request is useful only when it changes the condition “unable to get secure clock” and can be verified against the original evidence.
Representative case: A subscription transfer fails because the portable device has no readable trusted clock.
How to know the fix is real
Repeat the operation that originally returned it. Assert the exact HRESULT at the producing API in the failing “unable to get secure clock” fixture; then change only the relevant precondition and confirm that the corrected run completes without substituting a neighboring DRM result. After correcting it, verify the requested action and the final license-store, secure-clock, device or migration state relevant to “unable to get secure clock”.
Code-specific operational note
The user-facing message “A problem has occurred in obtaining the device's secure clock.
Technical references
Looking for a different code? Search another status or error code.