| Previous | Next |
| MQ_ERROR_CANNOT_HASH_DATA_EX | MQ_ERROR_CANNOT_CREATE_HASH_EX |
MQ_ERROR_CANNOT_SIGN_DATA_EX
Why the exact HRESULT matters
MQ_ERROR_CANNOT_SIGN_DATA_EX belongs to the Message Queuing HRESULT facility, but its useful meaning is narrower than a generic messaging failure. The result marks signature generation failed after message preparation. The private key/provider operation failed; the message should not be treated as authenticated.
For MQ_ERROR_CANNOT_SIGN_DATA_EX, authenticated MSMQ messages combine a sender identity, certificate, private key, hash/signature algorithm, and queue policy. When diagnosing MQ_ERROR_CANNOT_SIGN_DATA_EX, successful certificate parsing does not prove that the key is accessible to the sending process.
When diagnosing MQ_ERROR_CANNOT_SIGN_DATA_EX, MSMQ security material can live in the current user profile and be registered in directory services. In the MQ_ERROR_CANNOT_SIGN_DATA_EX path, services running under another account or without a loaded profile can observe a different certificate-store state.
Subsystem context
| Subsystem | MSMQ message authentication, certificate registration, signing, hashing, and encryption |
|---|---|
| Decisive boundary | certificate identity, key availability, provider capability, and message policy are independent checks |
| Code-specific focus | signature generation failed after message preparation |
| Primary recovery rule | Verify key access under the sender identity and provider/algorithm compatibility. |
When diagnosing MQ_ERROR_CANNOT_SIGN_DATA_EX, queue ACLs, certificate trust, private-key access, provider support, and destination authentication policy are independent. Test the layer named by the evidence. For MQ_ERROR_CANNOT_SIGN_DATA_EX, the code-specific boundary is signature generation failed after message preparation.
Minimum useful telemetry
- Certificate store location and security identity used by the process; associate it explicitly with
MQ_ERROR_CANNOT_SIGN_DATA_EX. - When diagnosing
MQ_ERROR_CANNOT_SIGN_DATA_EX, provider name/type, hash algorithm, and privacy/authentication properties; capture the value before cleanup or retry changes it. - In the
MQ_ERROR_CANNOT_SIGN_DATA_EXpath, whether the failure occurred while preparing, sending, storing, or validating the message; compare it with a known-good call using the same account and queue type. - For this
MQ_ERROR_CANNOT_SIGN_DATA_EXresult, record the queue path or format name, local/remote placement, transactional flag, caller SID, process build, and UTC correlation ID when they apply.
For MQ_ERROR_CANNOT_SIGN_DATA_EX, log certificate thumbprints, provider names, SIDs, GUIDs, lengths, and hashes where useful, but do not log private keys, symmetric keys, credentials, or confidential message bodies.
Step-by-step diagnosis
- Record the unsigned HRESULT,
MQ_ERROR_CANNOT_SIGN_DATA_EX, and the native API or COM method before a framework replaces it with a generic exception. - When diagnosing
MQ_ERROR_CANNOT_SIGN_DATA_EX, capture whether the failure occurred while preparing, sending, storing, or validating the message. - In the
MQ_ERROR_CANNOT_SIGN_DATA_EXpath, capture certificate store location and security identity used by the process. - Reproduce with the smallest queue/message/property set that still returns
MQ_ERROR_CANNOT_SIGN_DATA_EX; change one precondition at a time. - For
MQ_ERROR_CANNOT_SIGN_DATA_EX, verify the postcondition after the failed call: queue existence, message presence, directory object state, transaction outcome, or generated output may differ by result. - When diagnosing
MQ_ERROR_CANNOT_SIGN_DATA_EX, apply the code-specific recovery rule: Verify key access under the sender identity and provider/algorithm compatibility.
Retry and cleanup
Verify key access under the sender identity and provider/algorithm compatibility.
When diagnosing MQ_ERROR_CANNOT_SIGN_DATA_EX, do not hide this HRESULT behind an unlimited framework retry. In the MQ_ERROR_CANNOT_SIGN_DATA_EX path, require a verified precondition change and preserve the original correlation identifier across the next attempt.
Avoiding a false diagnosis
In the MQ_ERROR_CANNOT_SIGN_DATA_EX path, authentication failure is not synonymous with queue access denial. For this MQ_ERROR_CANNOT_SIGN_DATA_EX result, certificate stores, private keys, providers, signatures, and queue policy must be tested separately. The specific focus for MQ_ERROR_CANNOT_SIGN_DATA_EX remains signature generation failed after message preparation.
- In the
MQ_ERROR_CANNOT_SIGN_DATA_EXpath, A successful test under an interactive administrator account does not prove that the production service account has the same profile, token, directory access, or key permissions. - For this
MQ_ERROR_CANNOT_SIGN_DATA_EXresult, restarting MSMQ before collecting evidence can invalidate handles and erase the first useful event; it is a containment action, not a root-cause diagnosis.
Example
A service sending authenticated messages encounters MQ_ERROR_CANNOT_SIGN_DATA_EX. For MQ_ERROR_CANNOT_SIGN_DATA_EX, it tests store and private-key access under the production identity before changing queue security. When diagnosing MQ_ERROR_CANNOT_SIGN_DATA_EX, the acceptance test then changes only the decisive precondition and confirms both the HRESULT and the actual queue/message state.
A regression test should force MQ_ERROR_CANNOT_SIGN_DATA_EX, assert the raw value and relevant outputs, then correct only the documented precondition and verify the intended success or neighboring HRESULT.
References
- Microsoft: authenticated MSMQ message with an external certificate — source used for the
MQ_ERROR_CANNOT_SIGN_DATA_EXanalysis. - Microsoft: MSMQMessage object and message properties — source used for the
MQ_ERROR_CANNOT_SIGN_DATA_EXanalysis. - Microsoft: Windows certificate stores — source used for the
MQ_ERROR_CANNOT_SIGN_DATA_EXanalysis. - IETF RFC 5280: Internet X.509 PKI certificate profile — source used for the
MQ_ERROR_CANNOT_SIGN_DATA_EXanalysis. - Microsoft: Message Queuing error and information codes — source used for the
MQ_ERROR_CANNOT_SIGN_DATA_EXanalysis.
Looking for a different code? Search another status or error code.