Windows TPM AIK certificate enrollment fails against microsoftaik.azure.net with HTTP 400 / 0x80190190. The TPM EK is present, locally validated, and issued by the Intel ODCA 2 CSME MTP PCH SVN 01 PTT CA. The AIK service rejects the TPM identity with “No
Windows TPM AIK certificate enrollment fails against microsoftaik.azure.net with HTTP 400 / 0x80190190. The TPM EK is present, locally validated, and issued by the Intel ODCA 2 CSME MTP PCH SVN 01 PTT CA. The AIK service rejects the TPM identity with “No valid TPM EK/Platform certificate provided in the TPM identity request message.”
TPM manufacturer: Intel / INTC
TPM model: MTP
TPM version: 2.0
TPM firmware: 700.19.1011.2289
TPM revision: 1.59
TPM platform identifier: 02BC0013
EK issuer:
ODCA 2 CSME MTP PCH SVN 01 PTT CA
AIK Key ID:
77b63d9f8b73f5fbbd73ace7d8fbda37a6a7865f
AIK enrollment:
TpmDiagnostics.exe EnrollWindowsAIKCert
Result:
0x80190190 / HTTP 400
Server response:
"No valid TPM EK/Platform certificate provided in the TPM identity request message."
I have verified the Intel EK chain locally.
That should prevent first-line support from sending you through the standard:
“Enable TPM / enable Secure Boot / update BIOS”
script.