TPM AIK Enrollment Failure 0x80190190 / Intel PTT EK Validation Hello,

Bryan Manning 0 Reputation points
2026-10-06T23:09:54.13+00:00

Hello,

I am following up on my existing TPM/AIK attestation issue. I have completed additional diagnostics that further isolate the problem.

System: ASRock B860 Pro-A WiFi Intel PTT firmware: 700.19.1011.2289 Windows 11 / Secure Boot enabled

The TPM is present, ready, enabled, activated and owned. Windows TPM health reports the system as Attestable. RSA and ECC EK certificates are present in TPM NVRAM.

However, Windows AIK certificate enrollment continues to fail:

TpmDiagnostics.exe EnrollWindowsAIKCert

HTTP 400 / 0x80190190

CertificateServicesClient-CertEnroll Event 87 reports the Microsoft AIK service response:

“No valid TPM EK/Platform certificate provided in the TPM identity request message.”

Additional testing now shows:

  • TpmDiagnostics.exe ekchainNV → RSA EK chain builds but reports 0x10000 (partial chain)
  • TpmDiagnostics.exe ekchainNV -ecc → ECC chains also report 0x10000
  • Windows' registered EK certificate and the EK certificate stored in TPM NVRAM have identical SHA-256 hashes
  • Intel PTT reports RSA and ECC EK provisioning URLs at proserv.intel.com
  • proserv.intel.com is reachable over TCP 443
  • TpmDiagnostics.exe GetEkCertFromWeb fails with ASN.1 bad tag value met / 0x8009310B
  • TpmDiagnostics.exe GetEkCertFromWeb -ecc fails with the same 0x8009310B
  • The Intel EK certificate CRL distribution point references tcsci.intel.com, which currently returns NXDOMAIN, including through public DNS

The Windows AIK key itself exists, but no Windows AIK certificate is installed.

I have intentionally not cleared the TPM or manually installed/modified EK certificates.

I have now opened a case with Intel regarding the PTT/EK provisioning side.

Could this please be escalated to the Windows security/TPM attestation team to determine whether Microsoft's AIK service currently trusts/accepts this Intel ODCA 2 CSME PTT EK certificate chain?

Please let me know what additional TPM/Event Viewer logs are needed.

Windows for home | Windows 11 | Security and privacy
0 comments No comments

1 answer

Sort by: Most helpful
  1. Dio Xavier 296.9K Reputation points Volunteer Moderator
    2026-10-06T23:18:10.1033333+00:00

    Hello,

    Welcome to the Microsoft Windows Community.

    Good afternoon. Thank you for sharing the details of the situation. Which version of Windows 11 is installed on your device? In addition to the steps you've already mentioned, have you perhaps tried clearing the TPM keys?

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.