Request to onboard Intel ODCA 2 CSME EK Certificate Chain of i9‑13900HX to Azure Attestation Trust List, AIK Enrollment HTTP 400 Failure

哥 刀 0 Reputation points
2026-08-04T13:09:05.79+00:00

To Microsoft Azure Attestation Engineering Team,

I am an end-user with a Thunderobot Hunter S gaming laptop equipped with Intel Core i9‑13900HX processor equipped with firmware-based Intel PTT (Platform Trust Technology) TPM 2.0.

Verified device configuration and local TPM status

1. BIOS settings: Secure Boot enabled, CSM disabled, factory default PTT activation, no BIOS flashing, firmware modification, registry tampering or any TPM alteration.

2. System Version: Windows 11 latest official stable build, all Windows security patches fully updated.

3. Local inspection via  tpm.msc : On-board TPM 2.0 is healthy, functional and intact locally.

Core failure issue

When executing elevated command  certreq -enrollaik  to finish AIK remote attestation against endpoint  microsoftaik.azure.net , the server returns HTTP 400 Bad Request consistently.

After exporting and analyzing the EK certificate chain via TpmDiagnostics, the root CA is Intel ODCA 2 CSME series certificate. This batch of 13900HX PTT-generated EK issuing certificates has not been onboarded into the global trusted repository of Microsoft Azure Attestation service.

Practical consequence triggered by attestation failure

RICOCHET anti-cheat of Call of Duty Warzone relies on Microsoft remote TPM EK attestation validation. The untrusted certificate chain leads to persistent pop-ups requiring users to update BIOS firmware, which restricts me from accessing multiplayer ranked game modes.

I have never tampered with system security modules or adopted cheating tools; this validation error originates from incomplete CA admission instead of improper operation on my side.

Actions I have implemented to troubleshoot

1. Restored official factory BIOS firmware released by laptop OEM Thunderobot to rule out customized firmware defects.

2. Submitted technical tickets to Intel Customer Support and the laptop manufacturer, requiring them to coordinate with Microsoft to complete certificate chain admission.

3. Posted relevant error logs and symptom descriptions on Microsoft Learn Azure Attestation community together with dozens of users owning identical HX-series CPUs suffering the same 400 attestation error.

Formal request

I sincerely apply for your engineering team to review the Intel ODCA 2 CSME certificate chain corresponding to the 13900HX batch of mobile processors, incorporate the relevant root CA into the Azure Attestation trusted list, so that the PTT TPM can complete standard EK remote attestation normally.我诚挚地申请贵方工程团队审核与13900HX批次移动处理器相对应的Intel ODCA 2 CSME证书链,并将相关根CA纳入Azure Attestation可信列表,以便PTT TPM能够正常完成标准的EK远程证明。

I am ready to submit exported EK chain files, command error screenshots and TPM inspection logs 我已准备好提交导出的EK链文件、命令错误截图以及TPM检测日志我已准备好提交导出的EK链文件、命令错误截图以及TPM检测日志

or technical audit at any time.

Azure Virtual Machines
Azure Virtual Machines

An Azure service that is used to provision Windows and Linux virtual machines.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.