| Previous | Next |
| TPM_E_ENCRYPT_ERROR | TPM_E_INVALID_AUTHHANDLE |
TPM_E_DECRYPT_ERROR
The decrypt/unwrap stage could not recover valid plaintext
TPM_E_DECRYPT_ERROR (0x80280021) is returned after the TPM accepts enough of the command to attempt decryption but cannot produce valid plaintext. A wrong wrapping key, scheme, padding, or corrupted ciphertext can all reach this boundary.
Evidence to capture
Save the exact ciphertext bytes, key handle/public identity, encryption/wrapping scheme, padding parameters, command ordinal, and any transport-session details. Compare hashes with the producer side before changing the key.
Focused correction
Regenerate or submit ciphertext using the exact scheme and key expected by the TPM. If transport I/O fails before decryption, diagnose TPM_E_IOERROR instead of treating it as bad ciphertext.
Technical references
Looking for a different code? Search another status or error code.
