Mobile and Desktop Processors
Intel® Core™ processors, Intel Atom® processors, tools, and utilities
告知
Important Update: Community Platform Migration​. Learn more​>

COD

titiruka
ビギナー
506件の閲覧回数

Call of Duty Secure Attestation Failure — Support Report


ENGLISH (send this version)

Subject: Secure Attestation fails on Intel PTT / Z790 despite all requirements met — AIK enrollment succeeds but game still reports "BIOS Firmware: Update Required"

System

  • Motherboard: ASUS PRIME Z790-P
  • BIOS: 1836 (2026/05/14) — this is the newest version ASUS publishes. No newer BIOS exists.
  • CPU: Intel Core i7-13700KF
  • OS: Windows 11 Home, build 26200.9168
  • TPM: Intel PTT (firmware TPM), Manufacturer INTC, Version 600.18.1040.2765
  • Intel ME: 16.1.40.2765
  • Boot mode: UEFI, Secure Boot enabled

Current status

The Secure Attestation Wizard reports:

  • TPM 2.0: PASS
  • Secure Boot: PASS
  • Attestation: FAIL — "BIOS Firmware: Update Required"

The in-game message is the same: my PC does not meet security requirements, BIOS firmware update required, Failed Attestation Status applied.

What I have already done

  1. Confirmed TPM 2.0 is present and ready (Get-Tpm → TpmPresent: True, TpmReady: True).
  2. Confirmed Secure Boot is enabled (Confirm-SecureBootUEFI → True).
  3. Confirmed BIOS is on the latest available version (1836). ASUS publishes nothing newer.
  4. Diagnosed the underlying cause: the Windows certificate store contained zero Intel intermediate CA certificates, so the EK certificate chain could not be built.
  5. Extracted the three Intel intermediate certificates from TPM NV index 0x1C00100 (1980 bytes) using TpmDiagnostics, and imported them into Local Machine → Intermediate Certification Authorities:
    • CN=CSME ADL ROM CA
    • CN=CSME ADL SVN01 Kernel CA
    • CN=CSME ADL PTT 01SVN
  6. After this, AIK enrollment succeeds. Running certreq -enrollaik -config "" from an elevated prompt now returns:
    EnrollStatus(1): EnrolledHTTP/1.1 200 OKThe operation completed successfully. 0x0 (WIN32: 0)
    A new AIK certificate was issued by Microsoft's attestation service.

The problem

Microsoft's attestation service accepts my TPM and issues an AIK certificate. Windows reports the TPM as healthy and attestation-capable. Secure Boot is on. The BIOS is the newest one that exists for this board.

Despite all of that, Call of Duty still reports "BIOS Firmware: Update Required" and applies Failed Attestation Status.

Additionally, CODSecureAttestationWizard.exe crashes immediately on launch (it shows a loading spinner and then closes). No entry appears in the Windows Application event log.

Questions

  1. Since AIK enrollment now succeeds with Microsoft's service, what specifically is Call of Duty checking that still fails?
  2. What exactly triggers the "BIOS Firmware: Update Required" message? My BIOS is already the latest published version, so this message appears to be misleading.
  3. Is there a known incompatibility with Intel PTT firmware version 600.18.1040.2765 or the CSME ADL PTT 01SVN EK certificate hierarchy?
  4. Why does the attestation wizard crash on launch, and is there a log I can provide?

Multiple users on Intel's community forum report the identical symptom on Z790 boards with Intel PTT. This does not appear to be a configuration error on my end.

I can provide full command output, screenshots, or any diagnostic logs you need.


日本語(内容確認用)

件名: Intel PTT / Z790 環境で、要件をすべて満たしているのに Secure Attestation が失敗する

環境

  • マザーボード: ASUS PRIME Z790-P
  • BIOS: 1836(2026/05/14)— ASUSが公開している最新版。これ以上新しいものは存在しない
  • CPU: Intel Core i7-13700KF
  • OS: Windows 11 Home ビルド 26200.9168
  • TPM: Intel PTT、製造元 INTC、バージョン 600.18.1040.2765
  • Intel ME: 16.1.40.2765
  • ブートモード: UEFI、セキュアブート有効

現在の状態

認証ウィザードの結果:

  • TPM 2.0: 合格
  • セキュアブート: 合格
  • 認証: 失敗 —「BIOSファームウェア: アップデートが必要」

ゲーム内でも同じ表示。認証失敗ステータスが適用され、プレイリストが制限されている。

実施済みの対応

  1. TPM 2.0 が搭載され準備完了であることを確認
  2. セキュアブートが有効であることを確認
  3. BIOSが最新版(1836)であることを確認。ASUSはこれ以上公開していない
  4. 根本原因を特定: Windowsの証明書ストアに Intel の中間証明書が 1枚も入っていなかった。 そのため EK 証明書の連鎖が構築できていなかった
  5. TpmDiagnostics で TPM の NVインデックス 0x1C00100(1980バイト)から Intel中間証明書3枚を抽出し、ローカルコンピューターの中間証明機関へ登録:
    • CN=CSME ADL ROM CA
    • CN=CSME ADL SVN01 Kernel CA
    • CN=CSME ADL PTT 01SVN
  6. その結果、AIK登録が成功するようになった。 管理者権限で certreq -enrollaik -config "" を実行すると Enrolled / 0x0 が返り、 Microsoftの認証サービスから新しいAIK証明書が発行される

問題点

Microsoftの認証サービスは TPM を受理し、AIK証明書を発行している。 Windows は TPM を正常かつ認証可能と報告している。セキュアブートも有効。 BIOSはこのマザーボード向けに存在する最新版。

それでも Call of Duty は「BIOSファームウェア: アップデートが必要」と表示し、 認証失敗ステータスを適用する。

さらに、認証ウィザード(CODSecureAttestationWizard.exe)が起動直後に落ちる。 読み込み中の表示が出た後、すぐ閉じる。Windowsのアプリケーションログには記録が残らない。

質問

  1. Microsoftの認証サービスでAIK登録が成功しているのに、 Call of Duty は具体的に何を検査して失敗と判定しているのか
  2. 「BIOSファームウェア: アップデートが必要」は何をもって表示されるのか。 BIOSは既に最新版なので、この表示は誤りではないか
  3. Intel PTT ファームウェア 600.18.1040.2765、または CSME ADL PTT 01SVN の証明書階層に既知の非互換はあるか
  4. 認証ウィザードが起動直後に落ちる原因は何か。提出すべきログはあるか

Intelのコミュニティフォーラムには、Z790 + Intel PTT の組み合わせで 同一症状の報告が複数上がっている。当方の設定ミスではないと考えている。

コマンドの実行結果、スクリーンショット、診断ログなど、必要なものは提供可能。

0 件の賞賛
1 返信
CM_Intel
モデレーター
457件の閲覧回数

Hi there,


私は英語でしかサポートできないことをお知らせします。この返答はウェブ翻訳ツールを使って翻訳したので、少し誤訳があるかもしれません。

Sorry to hear you're experiencing this issue,and thank you for the detailed information you've shared so far also for translating the response.

 

To help us investigate further, could you please provide the following:

  • A video recording showing the issue, including the "BIOS Firmware: Update Required" message and the behavior when launching the Secure Attestation Wizard.
  • Was there ever a point when Call of Duty Secure Attestation worked correctly on this system? If so, do you recall which BIOS, Intel ME, Windows, or driver version was installed at that time?
  • Please share the exact Call of Duty version/build number you are using.
  • Which platform was the game installed from (Steam, Battle.net, Microsoft Store, etc.)? If possible, please provide the download/store link for the game version you are using.
  • Are any virtualization or security features enabled, such as Hyper-V, Memory Integrity, Device Guard, or Credential Guard?
  • Does the issue remain the same if BIOS settings are loaded to default values (while keeping Secure Boot and Intel PTT enabled)?
  • Have you tested with any earlier BIOS version where the issue was not present?
  • Share crash dumps in .dmp format

 

We would also appreciate an updated SSU (System Support Utility) report.

You can download the SSU tool using the link below:

How to get the Intel® System Support Utility Logs on Windows*

Note: While generating the SSU report, kindly uncheck the Networking option.

 

Additionally, if available, please share:

  • Screenshots of the attestation error.
  • Any logs, crash dumps, or diagnostic files related to CODSecureAttestationWizard.exe.
  • The exact date when you first noticed this behavior.

 

Once we receive the above information, we'll review it and continue investigating the issue with you.

返信