Hello,
I am following up on my existing TPM/AIK attestation issue. I have completed additional diagnostics that further isolate the problem.
System: ASRock B860 Pro-A WiFi Intel PTT firmware: 700.19.1011.2289 Windows 11 / Secure Boot enabled
The TPM is present, ready, enabled, activated and owned. Windows TPM health reports the system as Attestable. RSA and ECC EK certificates are present in TPM NVRAM.
However, Windows AIK certificate enrollment continues to fail:
TpmDiagnostics.exe EnrollWindowsAIKCert
HTTP 400 / 0x80190190
CertificateServicesClient-CertEnroll Event 87 reports the Microsoft AIK service response:
“No valid TPM EK/Platform certificate provided in the TPM identity request message.”
Additional testing now shows:
-
TpmDiagnostics.exe ekchainNV → RSA EK chain builds but reports 0x10000 (partial chain)
-
TpmDiagnostics.exe ekchainNV -ecc → ECC chains also report 0x10000
- Windows' registered EK certificate and the EK certificate stored in TPM NVRAM have identical SHA-256 hashes
- Intel PTT reports RSA and ECC EK provisioning URLs at
proserv.intel.com
-
proserv.intel.com is reachable over TCP 443
-
TpmDiagnostics.exe GetEkCertFromWeb fails with ASN.1 bad tag value met / 0x8009310B
-
TpmDiagnostics.exe GetEkCertFromWeb -ecc fails with the same 0x8009310B
- The Intel EK certificate CRL distribution point references
tcsci.intel.com, which currently returns NXDOMAIN, including through public DNS
The Windows AIK key itself exists, but no Windows AIK certificate is installed.
I have intentionally not cleared the TPM or manually installed/modified EK certificates.
I have now opened a case with Intel regarding the PTT/EK provisioning side.
Could this please be escalated to the Windows security/TPM attestation team to determine whether Microsoft's AIK service currently trusts/accepts this Intel ODCA 2 CSME PTT EK certificate chain?
Please let me know what additional TPM/Event Viewer logs are needed.