| Previous | Next |
| FVE_E_INVALID_PASSWORD_FORMAT | FVE_E_FIPS_PREVENTS_RECOVERY_PASSWORD |
FVE_E_FIPS_RNG_CHECK_FAILED
Where the operation stops
The value 0x80310036, named FVE_E_FIPS_RNG_CHECK_FAILED, is returned when the cryptographic random-number generator failed the self-check required by the active FIPS-restricted path. It belongs to the FIPS-restricted key management part of BitLocker rather than to generic file I/O.
The same volume can remain strongly encrypted while a recovery-password, passphrase, or export operation is rejected. Report the protector operation, not simply “BitLocker failed.” FIPS restrictions affect which protector, export, and key-derivation paths BitLocker may use. The volume encryption algorithm and the protector workflow are separate layers, so trace this result to the exact protector or key-management call.
| Question | What to verify |
|---|---|
| Which object failed? | The exact volume GUID, protector GUID, certificate or API target supplied by the caller. |
| Which state matters? | FIPS policy state, boot session, cryptographic provider events, system health, exact protector operation and whether the failure repeats after a clean boot. |
| What is the nearest false lead? | a policy prohibition on a protector type; this code says the approved RNG path itself did not pass its validation. |
Build a minimal diagnostic record
- Record FIPS policy state, boot session, cryptographic provider events, system health, exact protector operation and whether the failure repeats after a clean boot.
Change only the failed prerequisite
treat this as a platform cryptography failure, collect CNG and BitLocker events, and avoid creating replacement protectors until the RNG health issue is understood.
manage-bde -protectors -get C:
gpresult /h bitlocker-policy.html
State checks specific to FVE_E_FIPS_RNG_CHECK_FAILED
| Stage | How to interpret it |
|---|---|
| Before the call | Record the target identity and the pre-call FIPS-restricted key management state. The cryptographic random-number generator failed the self-check required by the active FIPS-restricted path. |
| At failure | Preserve FIPS policy state, boot session, cryptographic provider events, system health, exact protector operation and whether the failure repeats after a clean boot. This proves whether this result came from BitLocker itself or from a wrapper translating another result. |
| After correction | Treat this as a platform cryptography failure, collect CNG and BitLocker events, and avoid creating replacement protectors until the RNG health issue is understood. |
Official documentation
Looking for a different code? Search another status or error code.
