Site icon EfmSoft

What does HRESULT 0x80280044 (TPM_E_KEY_OWNER_CONTROL) mean?

 
Previous Next
TPM_E_INVALID_STRUCTURE TPM_E_BAD_COUNTER

TPM_E_KEY_OWNER_CONTROL

Which layer owns this HRESULT

TPM_E_KEY_OWNER_CONTROL (0x80280044) belongs to TPM 1.2 resources, delegation and contexts. The base What Is page already shows the short Windows message; the additional diagnostic value is that this result marks the key is marked for owner-controlled eviction, so a non-owner path cannot evict it from TPM 1.2 persistent control.

The first producer to identify for this HRESULT is the TPM resource, context or delegation manager, sometimes mediated by TBS virtualization. TBS can virtualize finite TPM resources, but a saved TPM context and a TBS virtual handle are not durable application IDs. Their validity depends on resource type, owning client context, TPM lifecycle and the exact save/load history.

The result value 0x80280044 should remain attached to the symbolic name. Some this result logs store the value as a negative signed integer; others expose only a generic CNG, WMI, BitLocker or enrollment message. Neither substitution identifies the key is marked for owner-controlled eviction, so a non-owner path cannot evict it from TPM 1.2 persistent control as precisely as it.

Diagnostic record

How to verify the distinction

Build the result minimal case around the original command contract. Use a disposable object when the request can write NV data, advance a counter, change authorization state or consume a lock transition. The comparison is valid only when the caller, TPM generation and security policy remain the same.

QuestionEvidence for this HRESULT
What exact state was rejected?the key is marked for owner-controlled eviction, so a non-owner path cannot evict it from TPM 1.2 persistent control
Which layer owns the result?The TPM resource, context or delegation manager, sometimes mediated by TBS virtualization.
What must be correlated?key handle, keyControl state, owner authorization path, creating command, requested eviction operation, and current ownership state
What is the controlled comparison?query or recreate a disposable owner-controlled key and compare owner-authorized versus ordinary eviction

Common false equivalences

ConstantCheckpoint represented by its standard message
TPM_E_BAD_COUNTERThe counter handle is incorrect — a separate checkpoint when compared with this result.
TPM_E_INVALID_STRUCTUREThe structure tag and version are invalid or inconsistent — a separate checkpoint when compared with this result.
TPM_E_CONTEXT_GAPThe gap between saved context counts is too large — a separate checkpoint when compared with it.

The codes above may appear in the same workflow, but they are not aliases. TPM_E_OWNER_CONTROL concerns context-saving an owner-evict key, whereas it concerns eviction control itself.

What a real fix looks like

Perform lifecycle management through the tpm owner or leave the key resident according to its policy. Do not persist volatile TPM or TBS handles as durable identifiers. A numeric handle can be valid only inside the creating context and lifecycle, even when its value looks unchanged after restart.

Proof for this HRESULT consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than it.

Source material


Looking for a different code? Search another status or error code.

Exit mobile version