Site icon EfmSoft

What does HRESULT 0x80280032 (TPM_E_NOTRESETABLE) mean?

 
Previous Next
TPM_E_AUDITFAIL_SUCCESSFUL TPM_E_NOTLOCAL

TPM_E_NOTRESETABLE

Interpret the condition first

TPM_E_NOTRESETABLE (0x80280032) belongs to TPM 1.2 command processing. This result means the caller attempted to reset a PCR that lacks the resettable attribute in the TPM 1.2 profile.

Build the command transcript

QuestionEvidence
What exact state was rejected?the caller attempted to reset a PCR that lacks the resettable attribute in the TPM 1.2 profile
Which layer owns the result?The TPM 1.2 command decoder and state machine.
What must be correlated?PCR index, PCR attributes, locality, platform profile, command ordinal, and whether the caller confused reset with extend
Controlled comparisonquery PCR attributes and perform the experiment only on a PCR documented as resettable for the active locality

Separate caller data from platform state. The caller data includes the command, structures, lengths, handles and flags; platform state includes TPM generation, provisioning, locality, lockout, resource inventory, firmware and the TBS service lifecycle. This result is actionable only after the rejected side is identified.

Test one hypothesis

Use the following verification sequence:

  1. Capture the unmodified failing input and 0x80280032.
  2. Query pcr attributes and perform the experiment only on a pcr documented as resettable for the active locality.
  3. Compare the first divergent field or state transition.
  4. Repeat the operation only after restoring the same baseline, with a bounded retry policy where the specification permits retry.

Do not merge these conditions

Other codeWhy a different remedy follows
TPM_E_NOTLOCALAttempt to reset a PCR register that requires locality and locality modifier not part of command transport.
TPM_E_AUDITFAIL_SUCCESSFULTPM audit construction failed and the underlying command was returning success.
TPM_E_BAD_TYPEMake identity blob not properly typed.

TPM_E_NOTLOCAL applies when a resettable PCR still requires a locality not present in the command. The difference determines whether to change serialization, authorization, resource lifetime, firmware/PPI state, command policy or only retry timing.

A safe recovery path

Correct the original boundary by choosing this direction: use PCR_Extend for measurement accumulation or select a profile-defined resettable PCR; software cannot add the resettable attribute. Do not clear ownership, delete keys or reset PCR-related state merely to see whether the message disappears; those actions can destroy the evidence and protected material while leaving serialization or command-order defects unchanged.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version