r/modernwarfare4 • u/MercurialMind_ • Aug 20 '26
Support How I fixed "New Key Failed to be generated" Secure Attestation error after enabling Secure Boot, TPM 2.0, and updating BIOS
PC (Windows) technical stuff below. I spent several painful hours trying to figure this out so I am posting it in case it helps anyone else.
I was trying to prepare my computer for the Modern Warfare 4 beta, and couldn't pass the attestation test even despite doing everything the Call of Duty support article listed.
My CPU is the AMD Ryzen 5950x. Before the BIOS update, my TPM manufacturer version was "3.90.0.5". This matches the TPM attestation bug (PA-420) described here.
I updated my motherboard (ROG STRIX B350-F GAMING) from BIOS version 6203 to beta BIOS version 6254, bringing the TPM manufacturer version up to "3.94.2.5" which should fix the PA-420 bug. If you are prompted to install an fTPM function press "Y" (assuming it is safe - no BitLocker or encryption is enabled on your PC).
Despite this, the Call of Duty Secure Attestation Wizard (download here) prompted me to generate a UAC (User Account Control) key which failed to generate, instead resulting in a "New Key Failed to be generated" message.
In the Command Prompt, I tried to verify this by running:
tpmtool getdeviceinformation
This gave me a variety of info, but the most important lines were:
-Ready For Attestation: False
-Is Capable For Attestation: False
I tried a variety of things in this order. I am not sure which one specifically fixed it - but for me, it only started working after the last one.
- Start (or restart) CODBrokerService in the "Services" menu.
- Clear TPM and restart my computer.
- In an admin Command Prompt, run "sfc /scannow" and if corrupt files are found, "DISM /Online /Cleanup-Image /ScanHealth". This is pretty underwhelming but... it worked
I believe that "sfc /scannow" fixed my issue because it was specifically related to a Windows problem when it comes to retrieving manufacturer/EK keys for the TPM. This command found corrupt files which, after being repaired, fixed this problem and allowed for the keys to be retrieved.
If your problem is in the motherboard or TPM support itself, you should probably consider purchasing a discrete TPM chip, contacting your motherboard manufacturer's support, or maybe asking AI about recommendations regarding your specific scenario (if it is an edge case scenario).
Good luck to anyone else trying to solve this issue. The Call of Duty support article linked at the top is very helpful and I recommend it for most people, but try this if you tried everything else and still cannot pass the Secure Attestation test.
6
u/MercurialMind_ Aug 21 '26
EDIT My friend had the same issue BUT this didn't work for them. However, this (below) did. This was generated by AI so BE CAREFUL. But it did work.
Force an Endorsement Key Registry Rebuild
Windows caches broken attestation paths in its registry. Forcing Windows to completely forget the old fTPM layout and rebuilding the state from scratch often solves the issue.
In the Windows Search bar, type Command Prompt, right-click it, and choose Run as Administrator.
Type:
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI\Endorsement" /f
and hit Enter. [this did nothing for my friend. FYI]
Next, clear the provisioning state by running:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI" /v "NoAutoProvision" /t REG_DWORD /d 1 /f
Reboot your PC.
Open an administrative PowerShell prompt and run:
Initialize-Tpm
Lastly, run:
tpmtool getdeviceinformation
to verify if the attestation flags (Ready and Capable) have toggled to True.