TPM event logger error after cpu swap, Event id 86

Arun Kandasamy 131 Reputation points
2021-09-02T14:44:56.32+00:00

I just swapped out my cpu, my previous chip had died and just received my replacement, both 5950x, Upon boot I received " New cpu installed, fTPM/PSP NV corrupted" and it asked me to reset, which I did, now im receiving the following error:

SCEP Certificate enrollment initialization for Local system via https://AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net/templates/Aik/scep failed:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Thu, 02 Sep 2021 14:27:28 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: d623448f-ee97-4ff8-a54c-c552e6a999be

Method: GET(203ms)
Stage: GetCACaps
Not found (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

How can I fix this?

Windows for business | Windows Client for IT Pros | User experience | Other

94 answers

Sort by: Oldest
  1. Norm Geltz 171 Reputation points
    2022-01-10T00:29:44.627+00:00

    Two things for you to consider, perform either or both at your discretion to validate how your TC environment is behaving:

    (1) Validate the state of your Attestation - Go To>Settings>Privacy & Security>Windows Security>Device Security. Ensure two things: (1) Secure Boot is on; then, (2) Go back to Device Security & click on "Security Processor Details" (located under the heading "Security processor". Note the state of Attestation for both "Attestation" and "Storage" - they should both read "Ready". If one or the other does not read "Ready", click on "Security Processor Troubleshooting" and follow the directions. This will renegotiate the Attestation Key on behalf of the Windows OS - this is rather key, note I stated the Attestation Key is being renegotiated on behalf of the Windows OS. This occurs via Windows as it communicates with the BIOS where UEFI and TPM are enabled. Then, the OS will Restart on its own. Go into Event Viewer to check for the SCEP Event ID86, and go back to Settings>etc. and check for Attestation again - it should be in the "ready" state for both "Attestation" and "Storage".

    (2) Notice what we did (above) we performed these operations WITHIN the OS, we did not perform these operations w/in the BIOS. But, again, this is rather key - you CAN and I might suggest (depending on your level of confidence and abilities) go directly into the BIOS, go to the screen you established TPM w/in the BIOS. Clear the TPM keys, then simply recreate the keys - use the "default" keys is fine. This simply means you're renegotiating the encrypted TPM keys and creating a newly certified Attestation Key.

    I hope this helps to address where you can find certain information and allow you to make informed decisions. If you have the time and/or inclination to learn more about TC, read the following. There are MANY areas on the Internet to find statements and documents regarding Attestation, Windows 11, TPM, etc. but note this - Windows 11 REQUIRES TC (Trusted Computing). Understanding what exactly that means will assist you greatly moving forward.

    https://en.wikipedia.org/wiki/Trusted_Computing

    Was this answer helpful?

    1 person found this answer helpful.

  2. Yves Geiser 21 Reputation points
    2022-01-10T07:38:26.957+00:00

    Hello,

    I did exactly what you described.

    1. I verified my ASUS BIOS that UEFI is set and CSM is off. Also I cleared the keys and verified that the TPM of the processor is set and not descret. (AMD 5800x)
    2. I verified the steps you explained and ran the wizard to be really sure. This caused a reboot and enforced that I verify myself during login with authenticator etc.. See the attachments. I also checked if the device manager shows the TPM 2.0 Module.
    3. So all looks good but I still get those error messages.

    Either AMD is not able and something is wrong on my CPU die or I really consider to throw Windows 11 out of the window to be honest. Microsoft needs to talk with hardware manufactures and agree on a simple process but this is a pain. I am a professional on IT and even I fail.... what is MS thinking of users like non professionals, not understanding of how keys do work? Do not except that people read manuals about security standards... they will return the devices simple as it is and buy an apple product.

    So - I am willing to help and deliver what it takes. So what do you wanna see else?

    163500-security-processor-details.jpg
    163486-device-security.jpg

    Was this answer helpful?


  3. Yves Geiser 21 Reputation points
    2022-01-15T16:37:17.617+00:00

    I'll switch back to Windows 10 and I suggest to do this as well. Even freeze's are random, this is bad for any M.2 drive on the long run.

    Looks that no one really cares about that issue.

    Was this answer helpful?

    0 comments No comments

  4. Norm Geltz 171 Reputation points
    2022-01-15T19:54:42.257+00:00

    Many may be interested in this read (below URL). IMO, I believe the absolute majority of BSOD issues (esp. for gamers) are related to increased (1) CPU L3 latency of the AMD family of processors and, (2) the notion of having to identify an AMD "best core" feature. This is my opinion ONLY, but others should read the article and formulate their own opinions regarding this type of information. Does this also effect SCEP attestation errors? Certainly the Attestation Key (assembled with CPU processor encrypted TC [Trusted Computing] algorithmic logic) must be able to accurately and consistently identify the "exact" processor. Does the "best core" processor get included in the Attestation Key? Does the "best core" processor change from minute-to-minute, after a Restart? I am completely unfamiliar with the process by which the Attestation Key is written at both the h/w & s/w level. None-the-less, something is amiss/askew with what appears to be AMD processors of a certain family and their ability to certify Attestation with the Azure server. I'm running Windows 11 OS build 22000.466 on ASUS PRIME X470-PRO Mobo, BIOS Vers 5861 AMD Ryzen 5 2600X with NVIDIA GeForce (GigaByte) GT1030 GPU. All of my drivers are up-to-date. I'm not a gamer, I have never received a BSOD, but the SCEP error comes and goes. My attestation as witnessed via the W11 OS is consistently in "ready" state.

    https://www.pcworld.com/article/544602/windows-11-hurts-amd-ryzen-performance-even-more-than-we-thought.html

    Was this answer helpful?

    1 person found this answer helpful.

  5. Yves Geiser 21 Reputation points
    2022-01-16T08:17:16.307+00:00

    For all the future visitors. As for today, to get rid of the random freezes and error messages. This is the only way to fix the current issue.

    Switch back to Windows 10 (Win11 licenses do work for Win10) and turn off TPM within BIOS. All errors are gone on Windows 10.

    I own hardware from MSI and ASUS with the current 5k series line up and can say, that this is a AMD and MS issue. I expect it will also require a BIOS fix. For me it looks that this TPM reset and restore feature doesn't work 100% properly. I would not suggest to encrypt the harddisk on win11 because of that shaky setup.

    EDIT also you m.2 disk does log all hard resets and propably this is not good for m.2 disks to get turned off like this frequently... otherwise it would be logged...

    I remain follow this issue on my second build that remains on Windows 11.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.