| Previous | Next |
| MQ_ERROR_CORRUPTED_PERSONAL_CERT_STORE | MQ_ERROR_BAD_SECURITY_CONTEXT |
MQ_ERROR_COMPUTER_DOES_NOT_SUPPORT_ENCRYPTION
Operational meaning
Applications should keep MQ_ERROR_COMPUTER_DOES_NOT_SUPPORT_ENCRYPTION attached to the exact MSMQ call that produced it. The result marks destination capability cannot satisfy privacy request. The sending path requires encryption support that the target computer or installed MSMQ version does not expose.
Encryption capability and message authentication are related but distinct. When diagnosing this result, preserve provider, algorithm, certificate, key-container, and queue authentication/privacy settings rather than collapsing them into one “SSL” diagnosis.
MSMQ security material can live in the current user profile and be registered in directory services. Services running under another account or without a loaded profile can observe a different certificate-store state.
Where the condition occurs
| Subsystem | MSMQ message authentication, certificate registration, signing, hashing, and encryption |
|---|---|
| Relevant condition | certificate identity, key availability, provider capability, and message policy are independent checks |
| Code-specific focus | destination capability cannot satisfy privacy request |
Queue ACLs, certificate trust, private-key access, provider support, and destination authentication policy are independent. Test the layer named by the evidence. The code-specific boundary is destination capability cannot satisfy privacy request.
Evidence to preserve
- Whether the failure occurred while preparing, sending, storing, or validating the message.
- Certificate store location and security identity used by the process.
- Provider name/type, hash algorithm, and privacy/authentication properties.
Handling and recovery
Negotiate a supported deployment or remove privacy only when the application security design permits it.
Nearby failures
Authentication failure is not synonymous with queue access denial. Certificate stores, private keys, providers, signatures, and queue policy must be tested separately. Code-specific condition: destination capability cannot satisfy privacy request.
Worked example
A secure connector encounters it. It tests store and private-key access under the production identity before changing queue security.
Capability negotiation at the destination
It is a destination-capability boundary rather than a failure to hash one local message. Inventory the destination MSMQ version, available public-key properties, selected privacy level, and whether the queue was opened through a direct format name. Older or restricted installations can lack the encryption capability requested by the sender even though ordinary nonprivate messages are routable.
- Query the destination computer properties through the supported directory path and distinguish a missing enhanced key from a directory lookup failure.
- Verify that policy permits any fallback before changing
PROPID_M_PRIV_LEVEL; silently removing privacy changes the security contract. - Test another destination with known encryption support to prove whether the limitation follows the target computer or the sending host.
References
Looking for a different code? Search another status or error code.