Intel PTT AIK enrollment fails HTTP 400 – full Intel ODCA EK chain sent, rejected by Azure AIK service (i9-14900KF, Z790)

Faisal Abdullah 0 Reputation points
2026-10-07T15:01:24.9766667+00:00

SUMMARY Windows AIK certificate enrollment fails on my Intel PTT firmware TPM with HTTP 400 / 0x80190190 ("No valid TPM EK/Platform certificate provided in the TPM identity request message"). This blocks Call of Duty Secure Attestation ("New Key Generation Required" / BAD_KEYSET). TPM 2.0 and Secure Boot both pass. The client sends the full Intel on-die CA chain, so the failure appears to be server-side trust of the Intel ODCA issuing CA. SYSTEM - CPU: Intel Core i9-14900KF - Motherboard: ASUS PRIME Z790-P WIFI - BIOS: 1840 (09/18/2026); same result on 1836 - Intel ME firmware: 16.1.40.2765 (identical in BIOS 1836 and 1840) - TPM: Intel PTT, firmware 600.18.1040.2765, Vendor ID ADL, spec 1.38 - OS: Windows 11 25H2, build 26200 - Secure Boot: enabled, UEFI, standard keys (PK/KEK/db/dbx present; boot manager signed by Windows UEFI CA 2023) - VBS running; CSM disabled TPM STATUS - Present, enabled, activated, owned, ready - Ready For Attestation: True; Is Capable For Attestation: True - TPM Has Vulnerable Firmware: False - Not locked out EK CERTIFICATES (present in TPM NV) - 0x01C00002 RSA 2048 EK certificate (897 bytes) - 0x01C0000A ECC P-256 EK certificate (695 bytes) - 0x01C00016 ECC P-384 EK certificate (724 bytes) - 0x01C00100 EK certificate chain / EICA (1977 bytes) - EK issuer: CN=CSME ADL PTT 01SVN - EK serial: 74C04011F3A8221713D6C0C5D6B198B3 - EK thumbprint: 1E8135A54AF8EE97800C26AF7F7721E9FFA62A9D ERROR (certreq -enrollaik, 7 Oct 2026 14:54 GMT) - KeyId: INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363 - Issuing CA in identity request: CN=www.intel.com, OU=ODCA 2 CSME P_ADL 00002226 Issuing CA - Endpoint: https://INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363.microsoftaik.azure.net/templates/Aik/scep - x-ms-client-request-id: 50016986-83de-41c5-884d-77b0653e0ae2 - x-ms-request-id: a1aff807-8026-442c-8967-f40ee5d91095 - Response: HTTP/1.1 400 Bad Request {"Message":"No valid TPM EK/Platform certificate provided in the TPM identity request message."} - EnrollStage 220 (fails at SubmitRequest) - Same failure logged as Event 87 (CertificateServicesClient-CertEnroll) more than 50 times, including via AikCertEnrollTask run as SYSTEM. WHAT I HAVE RULED OUT - BIOS update: 1836 and 1840 both carry ME 16.1.40.2765. 1840 gives the same error. - BIOS settings: Firmware TPM enabled, Secure Boot Windows UEFI mode, CSM off. - Drivers: Intel chipset, Serial IO and ME drivers updated through ASUS DriverHub. - TPM health: tpmtool and Get-Tpm report healthy; restart-pending operation cleared. - Measured boot: TCG log present and valid. PCR7 binding "not possible" is caused only by a third-party (UEFI CA 2011) signed option ROM, which is unrelated to AIK enrollment. - I have not cleared the TPM, because the EK is hardware-derived and would regenerate under the same CA. MICROSOFT Q&A RESPONSE (7 Oct 2026) A moderator concluded the failure occurs during validation of the EK certificate trust chain, not TPM health, Secure Boot or Windows, and noted that an empty AdditionalCertificates field is not conclusive. The diagnostics above confirm the chain is present in NV index 0x01C00100 and is sent with the request. QUESTIONS 1. Microsoft: Is "ODCA 2 CSME P_ADL 00002226 Issuing CA" present in the Azure AIK service trust pool? If not, can it be added? 2. Intel: Is this EK and issuing CA valid for AIK attestation, and has Intel provided this ODCA issuing CA to Microsoft for trust? 3. ASUS: Is a newer ME/CSME firmware planned for this board that changes the PTT EK chain? The same KeyId appears in other public reports on Intel PTT systems, so this likely affects more users. Attachments: tpm-info.txt, ek-info.txt, certreq_output.txt, diagnostic_info.json

Windows for home | Windows 11 | Devices and drivers
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.