• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
OMEN by HP 45L Gaming Desktop PC GT22-3000i (A58QTAV)

HI all , after spending hours  trying to get COD MW4 working , it seems to be a HP issue , any one else had TPM issue  , see below 

 

System is an HP OMEN 45L GT22-3003na, board 8D2C, BIOS F.22, Intel PTT firmware 700.19.1005.2095.

TPM 2.0 reports Present, Ready, Ready For Attestation and has a valid EK certificate present.

Microsoft AIK enrollment using:

certreq.exe -enrollaik -f -q -machine -config ""

reaches Microsoft's AIK endpoint but returns HTTP 400 / 0x80190190:

No valid TPM EK/Platform certificate provided in the TPM identity request message.

Investigation of the Intel PTT NV endorsement certificate chain identified:

EK -> ODCA 2 CSME MTP PCH SVN 01 PTT CA -> ODCA 2 CSME MTP PCH SVN 01 Kernel CA -> ODCA 2 CSME MTP PCH ROM CA -> P_MTP PCH 00003145

The PTT CA certificate SHA1 is:

4E00F4EB6C3A100A9C7FC844759942F320A796E9

Its Authority Key Identifier is:

d55c584cd975f96abd0369daf0a9b17a7446e392

which correctly matches the Kernel CA Subject Key Identifier:

d55c584cd975f96abd0369daf0a9b17a7446e392

Both use compatible ECDSA P-384 / SHA-384 algorithms.

However Windows cryptographic validation of the PTT CA against the designated Kernel CA fails with:

CERT_TRUST_IS_NOT_SIGNATURE_VALID

TRUST_E_CERT_SIGNATURE

0x80096004

The PTT certificate was extracted directly from Intel PTT TPM NV and its SHA256 is:

79C4411150D8D637C528B4FA0ED319BF3C6E92B95889CE77A96A6B153EE9E3E3

An independently exported Windows copy has the identical SHA256, ruling out a stale/different Windows certificate copy.

Please escalate to the BIOS/Intel CSME/PTT engineering team and advise whether a BIOS/CSME firmware update or TPM endorsement-certificate reprovisioning procedure is available.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->