Site icon EfmSoft

What does HRESULT 0x8028005F (TPM_E_MA_AUTHORITY) mean?

 
Previous Next
TPM_E_MA_SOURCE TPM_E_PERMANENTEK

TPM_E_MA_AUTHORITY

Meaning beyond the built-in message

TPM_E_MA_AUTHORITY means the certified-migration authority named by the request is not the authority authorized for this key or ticket.

Decode the relevant state

QuestionEvidence
What exact state was rejected?the certified-migration authority named by the request is not the authority authorized for this key or ticket
Which layer owns the result?The certified-migration, key-policy or EK administrative checkpoint.
What must be correlated?authority digest and public key, CMK migration-authority list, ticket chain, source and destination data, and key creation attributes
Controlled comparisoncompare the authority identifier embedded in the CMK policy with the signer of a newly issued ticket

One-variable test

The one-variable check is to compare the authority identifier embedded in the CMK policy with the signer of a newly issued ticket. Record the before/after state that the command is allowed to change. If the operation can have side effects, use a disposable key, session, counter or NV index rather than production material.

  1. Capture this result and 0x8028005F at the first code-specific return boundary.
  2. Decode the relevant state: key attributes, authority tickets, source and destination identities, signatures and provisioning state.
  3. Run the controlled comparison once and preserve both binary transcripts.
  4. Verify the expected output or state transition instead of relying on absence of a UI message.

Differential diagnosis

Comparison codeBuilt-in distinction
TPM_E_PERMANENTEKAttempt to revoke the EK and the EK is not revocable.
TPM_E_MA_SOURCEMigration source incorrect.
TPM_E_BAD_SIGNATUREBad signature of CMK ticket.

It specifically answers whether the certified-migration authority named by the request is not the authority authorized for this key or ticket. In contrast, TPM_E_MA_TICKET_SIGNATURE means the authority may be right but its ticket signature does not validate.

Supported corrective direction

To remediate it, use the authorized migration authority or create a new key under the intended authority policy. Do not edit a signed ticket, migration blob or opaque private-key structure. Binary normalization, JSON conversion or base64 line handling can invalidate the authority and integrity relationships.

Authoritative references


Looking for a different code? Search another status or error code.

Exit mobile version