What does HRESULT 0xC00E006C (MQ_ERROR_CANNOT_SET_CRYPTO_SEC_DESCR) mean?

 
Previous Next
MQ_ERROR_ENCRYPTION_PROVIDER_NOT_SUPPORTED MQ_ERROR_CERTIFICATE_NOT_PROVIDED

MQ_ERROR_CANNOT_SET_CRYPTO_SEC_DESCR

The crypto key-container ACL update failed

MQ_ERROR_CANNOT_SET_CRYPTO_SEC_DESCR () means MSMQ or its certificate-registration path failed specifically while applying a security descriptor to cryptographic key material. Queue ACLs and message permissions are not the same object.

Evidence to capture

Record account/service identity, certificate/key container, provider/CSP/KSP, existing ACL, requested security descriptor, and the first CryptoAPI/Win32 access result.

Focused correction

Grant only the required account access to the actual key container using supported certificate/key tools, then retry registration. Do not broaden queue permissions or add Everyone to the key ACL.

Technical references


Looking for a different code? Search another status or error code.