Site icon EfmSoft

What does HRESULT 0x8028003E (TPM_E_READ_ONLY) mean?

 
Previous Next
TPM_E_BAD_LOCALITY TPM_E_PER_NOWRITE

TPM_E_READ_ONLY

Technical interpretation

TPM_E_READ_ONLY (0x8028003E) belongs to TPM 1.2 nonvolatile-storage policy. This result means the TPM 1.2 NV index definition allows reads but not the attempted write.

The first producer to identify is the TPM 1.2 NV permission and lifecycle checks. TPM 1.2 NV indices combine permissions, authorization mode, locality masks and lock semantics. Two indices of the same size can behave differently because those attributes were fixed when each index was defined.

Keep the result value 0x8028003E attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.

Inputs and state to capture

  • Producer: the TPM 1.2 NV permission and lifecycle checks.
  • Rejected invariant: the TPM 1.2 NV index definition allows reads but not the attempted write.
  • What to capture: NV index, permission bits, define-space request that created it, requested offset and length, and any permanent or startup-clear locks.
  • Safe comparison: query the public NV definition and write a disposable index created with explicit write permission.

Validate without broad changes

QuestionEvidence
What exact state was rejected?the TPM 1.2 NV index definition allows reads but not the attempted write
Which layer owns the result?The TPM 1.2 NV permission and lifecycle checks.
What must be correlated?NV index, permission bits, define-space request that created it, requested offset and length, and any permanent or startup-clear locks
Controlled comparisonquery the public NV definition and write a disposable index created with explicit write permission

Neighboring response codes

ConstantMeaning
TPM_E_PER_NOWRITEThere is no protection on the write to the NV area.
TPM_E_BAD_LOCALITYThe locality is incorrect for the attempted operation.
TPM_E_FAMILYCOUNTThe family count value does not match.

The codes above may appear in the same workflow, but they are not aliases. TPM_E_AREA_LOCKED is a mutable lock-state issue, while it follows from the index permission model.

Fix and verify

Do not attempt to mutate a read-only index; create a new index with the correct policy if the application owns the data model. Do not undefine a production NV index until its public attributes and authorization policy have been recorded. NV policy is established at definition time, and destructive recreation can remove counters, certificates or provisioning state.

Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.

Source material


Looking for a different code? Search another status or error code.

Exit mobile version