Site icon EfmSoft

What does HRESULT 0x80280045 (TPM_E_BAD_COUNTER) mean?

 
Previous Next
TPM_E_KEY_OWNER_CONTROL TPM_E_NOT_FULLWRITE

TPM_E_BAD_COUNTER

The relevant TPM condition

TPM_E_BAD_COUNTER means the monotonic-counter handle does not identify the counter expected by the TPM 1.2 command.

The first producer to identify is the TPM resource, context or delegation manager, sometimes mediated by TBS virtualization. TBS can virtualize finite TPM resources, but a saved TPM context and a TBS virtual handle are not durable application IDs. Their validity depends on resource type, owning client context, TPM lifecycle and the exact save/load history.

Before changing the platform

Preserve these items before changing anything:

  • This result and 0x80280045, the exact returning method or command, and the first nested status.
  • counter handle, label, creation and release history, owner state, saved application mapping, and whether the TPM was cleared.
  • Record the TPM generation, manufacturer/firmware revision, Windows build, caller identity, and TBS/provider state.
  • The complete opaque request artifacts, redacting authorization secrets but not rewriting structure boundaries.

Test the contract

Run this focused check: enumerate current counter information and create a disposable counter instead of trusting a persisted handle. Do not combine the test with firmware updates, TPM clearing, account changes, key recreation and policy edits in the same trial; such a result cannot isolate this boundary.

StagePass condition
the monotonic-counter handle does not identify the counter expected by the TPM 1.2 commandThe original command reaches the next defined state without returning it.
Security behaviorVerification still uses the intended TPM, authorization, locality and policy.
Output integrityThe object, digest, event log or state transition produced after it validates independently.

Why another code is not equivalent

Related resultSeparate meaning
TPM_E_CONTEXT_GAPThe gap between saved context counts is too large.
TPM_E_KEY_OWNER_CONTROLThe key is under control of the TPM Owner and can only be evicted by the TPM Owner.
TPM_E_NOOPERATORNo operator AuthData value is set.

The practical distinction is that TPM_E_BAD_HANDLE is broader; it identifies the monotonic-counter namespace.

Evidence of success

The supported direction is to refresh the counter handle after lifecycle changes and store a stable application identifier separately. Do not persist volatile TPM or TBS handles as durable identifiers. A numeric handle can be valid only inside the creating context and lifecycle, even when its value looks unchanged after restart.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version