| Previous | Next |
| MQ_ERROR_ENCRYPTION_PROVIDER_NOT_SUPPORTED | MQ_ERROR_CERTIFICATE_NOT_PROVIDED |
MQ_ERROR_CANNOT_SET_CRYPTO_SEC_DESCR
The crypto key-container ACL update failed
MQ_ERROR_CANNOT_SET_CRYPTO_SEC_DESCR () means MSMQ or its certificate-registration path failed specifically while applying a security descriptor to cryptographic key material. Queue ACLs and message permissions are not the same object.
Evidence to capture
Record account/service identity, certificate/key container, provider/CSP/KSP, existing ACL, requested security descriptor, and the first CryptoAPI/Win32 access result.
Focused correction
Grant only the required account access to the actual key container using supported certificate/key tools, then retry registration. Do not broaden queue permissions or add Everyone to the key ACL.
Technical references
Looking for a different code? Search another status or error code.
