Article ID: 926187 - Last Review: November 13, 2006 - Revision: 2.3 Error message when you try to start a Windows Vista-based computer that is configured to use BitLocker: "The PIN has been entered incorrectly too many times"On This PageSYMPTOMSYou have a Windows Vista-based computer that is configured to use BitLocker Drive Encryption (BitLocker) together with Trusted Platform Module (TPM) security hardware. When you start the computer, you receive an error message that resembles the following: The PIN has been entered incorrectly too many times.
The Trusted Platform Module (TPM) is temporarily locking out attempts to unseal TPM sealed keys. The more times the PIN is entered incorrectly the longer the lockout time will become. It is not possible to predict when the lockout will be over. Please wait a few moments before attempting to reenter the PIN. Then ensure that you enter the correct PIN for this drive. CAUSEThis issue occurs because of the "anti-hammering" functionality that is included in the computer's TPM device. The anti-hammering functionality prevents access to the computer's TPM device for some time. RESOLUTIONTo resolve this issue, use one of the following methods, as appropriate for your situation: Method 1: Wait until the anti-hammering lockout period expiresIf you repeatedly retry a personal identification number (PIN) in a short period of time, you may increase the TPM lockout period. Also, as long as the TPM is locked out, you may be unable to gain access to the computer even if you enter the correct PIN. Therefore, it is best to wait until the lockout period expires. Then, enter the correct PIN to gain access to the computer.Method 2: Use the BitLocker Recovery Console to access the computer
Method 3: Reset the TPM lockout periodMicrosoft provides programming examples for illustration only, without warranty either expressed or implied. This includes, but is not limited to, the implied warranties of merchantability or fitness for a particular purpose. This article assumes that you are familiar with the programming language that is being demonstrated and with the tools that are used to create and to debug procedures. Microsoft support engineers can help explain the functionality of a particular procedure, but they will not modify these examples to provide added functionality or construct procedures to meet your specific requirements.You can use the ResetAuthLockOut function in a script to reset the TPM lockout period. To run this script, use the Windows Vista DVD to start the computer into Windows Recovery (WinRE). The following sample script illustrates how to use the ResetAuthLockOut function to reset the TPM lockout period. You must have the TPM owner password to use this method to reset the TPM lockout period. Note The TPM owner password is configured when you first enable BitLocker on the computer. This password differs from the TPM PIN. In an enterprise environment, the system administrator may have the TPM owner password. If BitLocker is configured for use with Active Directory, the TPM owner password is backed up to Active Directory. Warning If an incorrect password is provided to this function, the TPM device prevents this function from being used to reset the lockout period in later tries. In this scenario, you must wait until the TPM lockout period expires. Therefore, we recommend that you do not use this function to reset the TPM lockout period if you are not sure that you have the correct TPM owner password. MORE INFORMATIONThe Trusted Computing Group (TCG) requires that TPM 1.2 devices have a built-in anti-hammering functionality. This functionality is designed to help prevent dictionary attacks. A dictionary attack is a scenario where a malicious user repeatedly tries different possible PIN combinations to gain access to the computer. The TCG provides the specifications for TPM hardware. The particular anti-hammering specifications that each TPM device uses are specific to each hardware manufacturer. Many hardware manufacturers use an algorithm that increases the lockout period based on the number of incorrect access attempts. Because of these differences in the implementation of the anti-hammering functionality, we cannot determine the lockout period for a particular TPM device or for a particular scenario. For more information about TPM or about the TCG, visit the following TCG Web site: https://www.trustedcomputinggroup.org/
(https://www.trustedcomputinggroup.org/)
Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
For more information about how to configure drive encryption in Windows Vista, visit the following Microsoft Web sites: http://go.microsoft.com/fwlink/?LinkId=53779
(http://go.microsoft.com/fwlink/?LinkId=53779)
http://go.microsoft.com/fwlink/?LinkId=67232 (http://go.microsoft.com/fwlink/?LinkId=67232)
| Article Translations
|
Back to the top
