| Previous | Next |
| TPM_E_BAD_VERSION | TPM_E_AUDITFAIL_UNSUCCESSFUL |
TPM_E_NO_WRAP_TRANSPORT
Classify the layer correctly
TPM_E_NO_WRAP_TRANSPORT (0x8028002F) belongs to TPM 1.2 command processing. The base What Is page already shows the short Windows message; the additional diagnostic value is that this result marks the TPM 1.2 device or policy does not permit the requested wrapped transport-session behavior.
The first producer to identify for this HRESULT is the TPM 1.2 command decoder and state machine. TPM 1.2 is a command/response device with strict binary structures and stateful resources. Windows may present the device response as an HRESULT, but the diagnostic meaning still belongs to the command field, key, session, PCR, NV index or lifecycle check named by the TPM specification.
The result value 0x8028002F should remain attached to the symbolic name. Some this result logs store the value as a negative signed integer; others expose only a generic CNG, WMI, BitLocker or enrollment message. Neither substitution identifies the TPM 1.2 device or policy does not permit the requested wrapped transport-session behavior as precisely as it.
Incident worksheet
- Producer for this HRESULT: the TPM 1.2 command decoder and state machine.
- Rejected invariant: the TPM 1.2 device or policy does not permit the requested wrapped transport-session behavior.
- Decisive capture: transport attributes, whether wrapping is requested, key and auth handles inside the transport, locality, and capability data for transport support.
- Safe comparison: submit the same underlying command outside the wrapped transport in an isolated test context.
A reproducible comparison
Build the result minimal case around the original command contract. Use a disposable object when the request can write NV data, advance a counter, change authorization state or consume a lock transition. The comparison is valid only when the caller, TPM generation and security policy remain the same.
| Question | Evidence for this HRESULT |
|---|---|
| What exact state was rejected? | the TPM 1.2 device or policy does not permit the requested wrapped transport-session behavior |
| Which layer owns the result? | The TPM 1.2 command decoder and state machine. |
| What must be correlated? | transport attributes, whether wrapping is requested, key and auth handles inside the transport, locality, and capability data for transport support |
| What is the controlled comparison? | submit the same underlying command outside the wrapped transport in an isolated test context |
Boundaries often confused with this one
| Constant | Checkpoint represented by its standard message |
|---|---|
TPM_E_AUDITFAIL_UNSUCCESSFUL | TPM audit construction failed and the underlying command was returning a failure code also — a separate checkpoint when compared with this result. |
TPM_E_BAD_VERSION | The TPM cannot perform this version of the capability — a separate checkpoint when compared with this result. |
TPM_E_AUDITFAIL_SUCCESSFUL | TPM audit construction failed and the underlying command was returning success — a separate checkpoint when compared with it. |
The codes above may appear in the same workflow, but they are not aliases. TPM_E_TRANSPORT_NOTEXCLUSIVE reports loss of exclusivity after a transport exists; this code rejects wrapped transport support.
Restore service safely
Use an allowed transport form or redesign the workflow around ordinary authorized commands when wrapped transport is unavailable. Do not clear ownership, delete keys or reset PCR-related state merely to see whether the message disappears; those actions can destroy the evidence and protected material while leaving serialization or command-order defects unchanged.
Proof for this HRESULT consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than it.
Source material
- TCG: TPM 1.2 Main Specification — source for the checkpoint.
- TCG: TPM 1.2 Part 2 — Structures — source for the checkpoint.
- TCG: TPM 1.2 Part 3 — Commands — source for the checkpoint.
- Microsoft: TPM Base Services portal — source for the checkpoint.
Looking for a different code? Search another status or error code.
