Site icon EfmSoft

What does HRESULT 0x80290400 (TPM_E_PCP_ERROR_MASK) mean?

 
Previous Next
TPM_E_PPI_BLOCKED_IN_BIOS TPM_E_PCP_DEVICE_NOT_READY

TPM_E_PCP_ERROR_MASK

What failed and what did not

TPM_E_PCP_ERROR_MASK means the bit mask used to identify Platform Crypto Provider TPM-related HRESULTs, not a failure returned for a key operation by itself.

The first producer to identify is CNG/NCrypt provider error mapping above TBS and the TPM. The Microsoft Platform Crypto Provider exposes TPM-backed keys through CNG. Provider HRESULTs may wrap key-policy, TBS or device failures, so the exact provider operation and nested status are essential.

Keep the result value 0x80290400 attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.

Collect a useful trace

  • Producer: CNG/NCrypt provider error mapping above TBS and the TPM.
  • Rejected invariant: the bit mask used to identify Platform Crypto Provider TPM-related HRESULTs, not a failure returned for a key operation by itself.
  • What to capture: the full HRESULT from NCrypt or certificate enrollment, provider name, operation, key property, nested TPM/TBS status, and hexadecimal representation.
  • Safe comparison: classify a captured provider HRESULT with the mask, then decode the actual low-order PCP error rather than invoking a provider operation for the mask.

Narrow experiment

QuestionEvidence
What exact state was rejected?the bit mask used to identify Platform Crypto Provider TPM-related HRESULTs, not a failure returned for a key operation by itself
Which layer owns the result?CNG/NCrypt provider error mapping above TBS and the TPM.
What must be correlated?the full HRESULT from NCrypt or certificate enrollment, provider name, operation, key property, nested TPM/TBS status, and hexadecimal representation
Controlled comparisonclassify a captured provider HRESULT with the mask, then decode the actual low-order PCP error rather than invoking a provider operation for the mask

Similar-looking outcomes

ConstantMeaning
TPM_E_ERROR_MASKThis is an error mask to convert TPM hardware errors to win errors.
TPM_E_FAILThe operation failed.
TPM_E_SHA_THREADThere is no existing SHA-1 thread.

The codes above may appear in the same workflow, but they are not aliases. TPM_E_ERROR_MASK classifies the broader TPM hardware mapping family, while this mask is tied to Platform Crypto Provider errors.

Operational response

Preserve provider and nested error values in telemetry and fix the concrete pcp condition. Do not treat a provider mask as a key-specific diagnosis. Preserve the exact NCrypt status and the inner TPM/TBS result before changing certificate or key enrollment policy.

Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.

Source material


Looking for a different code? Search another status or error code.

Exit mobile version