• ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
The HP Community is where owners of HP products, like you, volunteer to help each other find solutions.
Archived This topic has been archived. Information and links in this thread may no longer be available or relevant. If you have a question create a new topic by clicking here and select the appropriate board.
HP Recommended
PC's/Notebooks with SLB 9670
Microsoft Windows 10 (64-bit)

 

Windows 10 64 bit on HP Prodesk 600 G2. But could also be an issue of other systems with Infineon TPM 1.2 SLB 9670 and Windows 10 Build 15063.674.

 

I get the following Event  87 (CertificateServicesClient-CertEnroll):

 

Fehler bei der SCEP-Zertifikatregistrierung für xxxxx\yyyyyy$ über https://IFX-KeyId-[...here 40 characters...].microsoftaik.azure.net/templates/Aik/scep:

SubmitDone
GetCACertChain: OK
HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Thu, 12 Oct 2017 20:11:49 GMT
Pragma: no-cache
Content-Length: 5185
Content-Type: application/x-x509-ca-ra-cert
Expires: -1
Server: Microsoft-IIS/8.5
x-ms-request-id: [...here 16 characters...]
Strict-Transport-Security: max-age=31536000;includeSubDomains
X-Content-Type-Options: nosniff
X-Powered-By: ASP.NET

Methode: POST(3812ms)
Phase: SubmitDone
Ungültige Anforderung (400). 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)

 

The event comes from the task AikCertEnrollTask (\Microsoft\Windows\CertificateServicesClient). Something in the request for the AIK Certificate leads to a reject from the microsoft server. The server is reachable and replies, but rejects the request. This behaviour came with patch day October to Build 15063.674.  I did also try the TPM 2.0 firmware with everything else unchanged. This went well. But TPM 2.0 is not an option for me because I still need MBR partitioning.

 

The TPM is on firmware 6.43.243.0

 

Of course I also erased and reinitialized the TPM.

 

Does anyone see the same behavoiur or has a solution?

 

Archived This topic has been archived. Information and links in this thread may no longer be available or relevant. If you have a question create a new topic by clicking here and select the appropriate board.
† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.