Summary
On a Pluton-equipped laptop, Windows TPM key attestation is permanently broken after a Pluton firmware SVN update renamed the on-die issuing CA without re-issuing the EK certificate. AIK enrollment fails locally with 0x80070490 before any network contact.
Hardware/OS: HP OMEN 16-ap0xxx, AMD Ryzen AI 9 365 ("Strix Point"), Microsoft Pluton TPM (manufacturer MSFT, firmware 10.6.0.4), BIOS AMI F.13 (latest for this model), Windows 11 Pro 25H2 build 26200, Secure Boot on, fully patched.
Symptoms
-
tpmdiagnostics EnrollWindowsAIKCert → TpmEnrollWindowsAikCertificate hr: 0x80070490 (Element not found) — instantly, with zero network I/O (verified via DNS-cache trace).
- Registry
HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI\AIKEnrollmentErrorCode = 0x80070490.
- Every attestation consumer fails: Device Health Attestation, and anti-cheat attestation via Microsoft Azure Attestation (e.g. Call of Duty RICOCHET reports "Failed Attestation Status ... BIOS firmware: Update Required" — although BIOS is the latest).
- Windows Security → Device security shows "Standard hardware security is not supported."
- Meanwhile the pre-attestation health check passes: TPM-WMI event 1038, MeasuredBoot JSON
HealthStatus: "Attestable", EkCertIsAvailable: true, PcrsMatchTcgLog: true, VBS running.
Root cause (on-device evidence)
| Item |
Value |
EK leaf cert (NV 0x01C00002) — Issuer CN |
PLUTON Firmware SVN04, OU=FIRMWARE EKICA DFID00B20F40 |
On-die intermediate (NV 0x01C00100) — Subject CN |
PLUTON Firmware SVN06, OU=FIRMWARE EKICA DFID00B20F40 |
| Leaf AKI vs. intermediate SKI |
Identical (same signing key, verified) |
| Leaf RSA modulus vs. live TPM EKpub |
MATCH (verified with tpmdiagnostics GetEk) |
A Pluton firmware SVN update (SVN04 → SVN06) renamed the FIRMWARE EKICA subject while keeping the same key, and the EK leaf was never re-issued to reference the new name.
-
certutil -verify builds the full chain via AKI key-ID matching once the on-die intermediates + AMD factory chain (from TrustedTpm.cab) are imported:
leaf → PLUTON Firmware SVN06 → DEVICE EKICA (02EE…) → AMD Pluton Per-Product Factory NON-FIPS EK ICA DFID00B20F40 → AMD Pluton Global Factory ICA → AMD Root CA R4 ✔
- But TpmCoreProvisioning's AIK enrollment resolves the EK issuer by exact subject name, finds no CA named
PLUTON Firmware SVN04, and returns ERROR_NOT_FOUND.
Already tried (no effect)
- TPM clear from Windows and from BIOS — both re-provision the same stale-named leaf.
-
tpmdiagnostics GetEkCertFromWeb → 0x80090029 (no online EK re-issuance path exists for Pluton).
- BIOS update to latest (F.13), Secure Boot re-enrollment, full Windows Update,
InstallEkCertThroughCoreProv (succeeds but re-installs the same leaf).
- Firmware SVN is anti-rollback — the old issuer name cannot return.
Ask
Please route this to the TPM/Pluton servicing team. Two possible fixes:
- A Pluton firmware update that re-issues the EK leaf under the current intermediate name (SVN06), or
- Change AIK enrollment issuer resolution to use AKI key-ID matching instead of exact subject-name matching — the same class of fix as KB5007253 shipped for Intel on-die CAs.
Cross-reference (same case, HP side): HP Support Community — OMEN 16-ap0xxx TPM attestation broken (AIK error 0x80070490)
Full tpmdiagnostics dumps, NV certificate reads, and event logs are available on request.