Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

Anonymous
2019-04-28T20:45:27+00:00

Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography.  So my Win 10 machine is insecure?  I have run sfc /scannow  and  Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck.  And I hardly even use my Win 10 machine - there are almost no apps on it yet.  My actual Win 10 build is 17134.706

Here are the latest five Cryptography-related Audit Failures, from two reboots:

LATEST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:27:52 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:        DESKTOP-3#####N

    Logon ID:        0x3EC24

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />

    <EventRecordID>19582</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="948" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ec24</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FOURTH OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 12:26:51 PM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />

    <EventRecordID>19552</EventRecordID>

    <Correlation />

    <Execution ProcessID="880" ThreadID="1004" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

THIRD OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:29:28 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        DESKTOP-3#####N[My user name]

    Account Name:        [My user name]

    Account Domain:    DESKTOP-3#####N

    Logon ID:        0x3EF94

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    Microsoft Connected Devices Platform device certificate

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />

    <EventRecordID>19387</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="928" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-21-[My Identifier 10-9-10 digits]-1001</Data>

    <Data Name="SubjectUserName">[My user name]</Data>

    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>

    <Data Name="SubjectLogonId">0x3ef94</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

SECOND OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

FIRST OF FIVE:

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          4/28/2019 11:28:27 AM

Event ID:      5061

Task Category: System Integrity

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      DESKTOP-3#####N

Description:

Cryptographic operation.

Subject:

    Security ID:        LOCAL SERVICE

    Account Name:        LOCAL SERVICE

    Account Domain:        NT AUTHORITY

    Logon ID:        0x3E5

Cryptographic Parameters:

    Provider Name:    Microsoft Software Key Storage Provider

    Algorithm Name:    UNKNOWN

    Key Name:    [Hex number]

    Key Type:    User key.

Cryptographic Operation:

    Operation:    Open Key.

    Return Code:    0x80090016

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

    <EventID>5061</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12290</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />

    <EventRecordID>19363</EventRecordID>

    <Correlation />

    <Execution ProcessID="884" ThreadID="992" />

    <Channel>Security</Channel>

    <Computer>DESKTOP-3#####N</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="SubjectUserSid">S-1-5-19</Data>

    <Data Name="SubjectUserName">LOCAL SERVICE</Data>

    <Data Name="SubjectDomainName">NT AUTHORITY</Data>

    <Data Name="SubjectLogonId">0x3e5</Data>

    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>

    <Data Name="AlgorithmName">UNKNOWN</Data>

    <Data Name="KeyName">[Hex number]</Data>

    <Data Name="KeyType">%%2500</Data>

    <Data Name="Operation">%%2480</Data>

    <Data Name="ReturnCode">0x80090016</Data>

  </EventData>

</Event>

So, what the *** are these, and how do we fix?  No guesses - just the real fix.


glnzglnz

☺ In the office, Dell Optiplex 7040 with 8GB RAM, Win 7 Pro 64-bit and Office 2010

☻ At home, Dell Optiplex 7010 with 16GB RAM dual-booting Win 7 Pro 64-bit (now with Office 365 Home) and Win 10 Pro 64-bit

♥ Also still have Dell Optiplex 755 with 4GB RAM with Win XP Pro SP3 (which still gets updates with the POS hack) and Office 2003

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

48 answers

Sort by: Oldest
  1. Anonymous
    2019-05-11T20:27:49+00:00

    Larry - For my particular issue, no luck.

    In regedit, after my deletion and reboot, the ROOTS folder definitely changed.  For one thing, it is now ALL CAPS - ROOTS, not Roots.

    Also, it has a new Permission for "Software and hardware certificates or a smart card" - never saw that before - as Read.

    But on two reboots now, I continue to get at least two of the same AUDIT FAILURES.

    As you're very knowledgeable, is there anything I should check?

    Thanks again!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-05-11T20:57:56+00:00

    I have had 3 audit failures per day  for the past year(or more), ever since upgrading to 1803. I have neither Chrome nor  Nvidia graphics on my system. I have never found a way to get rid of these audit failures but have also had no problems that I know of regarding security. I am on 1809 now and the same 3 still persist. It is a bit unnerving to see Audit failures. I did find something long ago that suggested that if you look at the successes you will see a corresponding success for each of the failures. Something to do with the way the request is processed. I am sorry but I have lost the web site that had this explanation. I have long since just ignored this although every once in a while I do look just to see if they are still there. I am going to follow this thread to see if someone is able to solve the mystery of these failures. Thanks for the info so far and feel the right trail is being followed. I have the user key, and 2 connected devices platform audit failures. I do not use one drive and my laptop is used by only me.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-05-11T21:05:28+00:00

    Glnz:

    The HKCU path is SystemCertificates/Root

    HKLM is Systemcertificates/ROOT

    No 's' in either case.

    ProtectedRoots is only under HKCU: ...SysCerts/Root/ProtectedRoots

    This is the only Roots (with s) that I see.

    The SmartCard read permission is standard (for both HKCU and HKLM...Root).

    The best way to view the permissions is from the Permissions>Advanced tab - you can see them all at once in table format.

    Since the rebuild didn't fix the audit alert, I'll need more details.  If you ran the automated registry cleanup, send me the logs.  You can attach them to the related Chrome CryptSvc thread here.  If you did it manually, a snapshot of HKCU...Root: Permissions>Advanced would help.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-05-11T21:08:09+00:00

    ConiGL - Well, it's a relief to know I'm not the only one, and also that I should not rush to upgrade to 1809 as you continue to have the problem.

    I'll look for matching successes later.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2019-05-11T21:18:45+00:00

    Glnz: The critical permission is for 

     HKCU...SystemCertificates\Root\ProtectedRoots

    It should look like: 

    Also significant:

    Integrity Level: High Mandatory

    Enable Inheritance display: means Inheritance is currently off, as designed.

    Was this answer helpful?

    0 comments No comments