Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

Anonymous
2019-04-28T20:45:27+00:00

Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography.  So my Win 10 machine is insecure?  I have run sfc /scannow  and  Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck.  And I hardly even use my Win 10 machine - there are almost no apps on it yet.  My actual Win 10 build is 17134.706

Here are the latest five Cryptography-related Audit Failures, from two reboots:

LATEST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:27:52 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:        DESKTOP-3#####N

    Logon ID:        0x3EC24

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />

    <EventRecordID>19582</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="948" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ec24</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FOURTH OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:26:51 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />

    <EventRecordID>19552</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="1004" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

THIRD OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:29:28 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:    DESKTOP-3#####N

    Logon ID:        0x3EF94

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />

    <EventRecordID>19387</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="928" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ef94</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

SECOND OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FIRST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

So, what the *** are these, and how do we fix?  No guesses - just the real fix.


glnzglnz

☺ In the office, Dell Optiplex 7040 with 8GB RAM, Win 7 Pro 64-bit and Office 2010

☻ At home, Dell Optiplex 7010 with 16GB RAM dual-booting Win 7 Pro 64-bit (now with Office 365 Home) and Win 10 Pro 64-bit

♥ Also still have Dell Optiplex 755 with 4GB RAM with Win XP Pro SP3 (which still gets updates with the POS hack) and Office 2003

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

48 answers

Sort by: Most helpful
  1. Anonymous
    2019-06-07T03:23:41+00:00

    Coni - check out the possible cure at

    < THIS 10 FORUM POST >

    and the immediately two following posts by the same guy "EyeInTheSky".

    What do you think?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-06-01T15:23:44+00:00

    So far so good. On the reboot after it installed I had 4 of them but they went away. I have had it since the 24th of May and there has been none since the first boot after installation. The 4 that failed were all for the guest account  and were null sid, so were perfectly understandable as Microsoft removed guest account .  The guest account has been disabled by Microsoft so with next boot those are gone. No more problems.

    Also the DCOM errors have been moved to Warnings instead of errors which is great too.(They are not actually errors anyway).They are an app trying to connect to the internet at boot that should not have those permissions. I would have liked to see them moved to information instead. Ah well maybe someday.

    I would go for it.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-06-01T12:59:34+00:00

    Coni - 1903 still good?  I might go for it this weekend.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-05-27T19:25:36+00:00

    Thinking back on this I seem to remember in the forum thread  I read that it is checking the keys in a different way ? which fails the audit but then checks with ECDSA_P256 which is then a success. I wish I knew or could find easier documentation from Microsoft.I really feel it is just a jumble of new and old code that has never been corrected in the 1803 and1809 update.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2019-05-26T19:39:14+00:00

    I did some more digging.  I looked at the sequence of Audit Successes before and after each Audit Failure - maybe they're related?  Maybe the steps mean something?

    In the link below, I have pasted the "General" subwindows for the Event Viewer events closely preceding, including and following each of the two Audit Failures in my most recent bootup. 

    There seems to be some kind of pattern of the machine looking at the key, DELETING it, then looking for it again, then throwing the AUDIT FAILURE - maybe because it just deleted the key and the key isn't there any more - and then re-creating the key.  Is the AUDIT FAILURE just the good result of a test that the key was successfully deleted?

    But WHY is the machine doing this?  Why delete and recreate?  What's really going on?

    Here's the link to the Word Online document in which I've pasted both Event Viewer sequences.

    <THIS LINK>

    Any thoughts?  (And am I interpreting the events correctly anyway?)

    Was this answer helpful?

    0 comments No comments