| Previous | Next |
| TPM_E_MA_SOURCE | TPM_E_PERMANENTEK |
TPM_E_MA_AUTHORITY
Meaning beyond the built-in message
TPM_E_MA_AUTHORITY means the certified-migration authority named by the request is not the authority authorized for this key or ticket.
Decode the relevant state
| Question | Evidence |
|---|---|
| What exact state was rejected? | the certified-migration authority named by the request is not the authority authorized for this key or ticket |
| Which layer owns the result? | The certified-migration, key-policy or EK administrative checkpoint. |
| What must be correlated? | authority digest and public key, CMK migration-authority list, ticket chain, source and destination data, and key creation attributes |
| Controlled comparison | compare the authority identifier embedded in the CMK policy with the signer of a newly issued ticket |
One-variable test
The one-variable check is to compare the authority identifier embedded in the CMK policy with the signer of a newly issued ticket. Record the before/after state that the command is allowed to change. If the operation can have side effects, use a disposable key, session, counter or NV index rather than production material.
- Capture this result and
0x8028005Fat the first code-specific return boundary. - Decode the relevant state: key attributes, authority tickets, source and destination identities, signatures and provisioning state.
- Run the controlled comparison once and preserve both binary transcripts.
- Verify the expected output or state transition instead of relying on absence of a UI message.
Differential diagnosis
| Comparison code | Built-in distinction |
|---|---|
TPM_E_PERMANENTEK | Attempt to revoke the EK and the EK is not revocable. |
TPM_E_MA_SOURCE | Migration source incorrect. |
TPM_E_BAD_SIGNATURE | Bad signature of CMK ticket. |
It specifically answers whether the certified-migration authority named by the request is not the authority authorized for this key or ticket. In contrast, TPM_E_MA_TICKET_SIGNATURE means the authority may be right but its ticket signature does not validate.
Supported corrective direction
To remediate it, use the authorized migration authority or create a new key under the intended authority policy. Do not edit a signed ticket, migration blob or opaque private-key structure. Binary normalization, JSON conversion or base64 line handling can invalidate the authority and integrity relationships.
Authoritative references
Looking for a different code? Search another status or error code.
