{"record":{"id":"e1ca76026826d39b","repo":"spring-projects/spring-security","slug":"unable-to-instantiate-oid","errorCode":null,"errorMessage":"Unable to instantiate Oid: ","messagePattern":"Unable to instantiate Oid: ","errorType":"exception","errorClass":"IllegalStateException","httpStatus":null,"severity":"error","filePath":"kerberos/kerberos-core/src/main/java/org/springframework/security/kerberos/authentication/KerberosMultiTier.java","lineNumber":126,"sourceCode":"\t\t\t\tbyte[] inToken = new byte[0];\n\t\t\t\toutToken = securityContext.initSecContext(inToken, 0, inToken.length);\n\n\t\t\t\testablished = securityContext.isEstablished();\n\t\t\t}\n\n\t\t\tjaasContext.addToken(targetService, outToken);\n\t\t}\n\t\tcatch (Exception ex) {\n\t\t\tthrow new BadCredentialsException(\"Kerberos authentication failed\", ex);\n\t\t}\n\t}\n\n\tprivate static Oid createOid(String oid) {\n\t\ttry {\n\t\t\treturn new Oid(oid);\n\t\t}\n\t\tcatch (GSSException ex) {\n\t\t\tthrow new IllegalStateException(\"Unable to instantiate Oid: \", ex);\n\t\t}\n\t}\n\n\tprivate KerberosMultiTier() {\n\t}\n\n}\n","sourceCodeStart":108,"sourceCodeEnd":134,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/kerberos/kerberos-core/src/main/java/org/springframework/security/kerberos/authentication/KerberosMultiTier.java#L108-L134","documentation":"KerberosMultiTier.createOid wraps GSSException from `new Oid(oid)` in an IllegalStateException. The static KERBEROS_OID constant initializes at class load; if the hard-coded Kerberos V5 OID string is rejected by the JGSS provider, class initialization fails.","triggerScenarios":"Class-loading of KerberosMultiTier when new Oid(\"1.2.840.113554.1.2.2\") throws GSSException — practically only with a broken/nonstandard JGSS provider or a JVM with a damaged security provider configuration.","commonSituations":"Unusual JVMs or custom security providers lacking standard GSS mechanism OID support; rarely seen on standard JDKs.","solutions":["Use a standard Oracle/OpenJDK JGSS provider that supports the Kerberos V5 OID.","Check java.security provider ordering does not remove the SunJGSS provider.","Inspect the GSSException cause for provider-specific details.","As a workaround, construct the Oid manually in your own code to test provider support."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"try {\n  new Oid(\"1.2.840.113554.1.2.2\");\n} catch (GSSException e) {\n  throw new IllegalStateException(\"JGSS provider lacks Kerberos V5 OID support\", e);\n}","typeGuard":null,"tryCatchPattern":"try {\n  Class.forName(\"org.springframework.security.kerberos.authentication.KerberosMultiTier\");\n} catch (Throwable t) {\n  LOG.error(\"JGSS provider cannot init KerberosMultiTier\", t);\n}","preventionTips":["Deploy on standard JDKs with the SunJGSS provider enabled.","Do not remove SunJGSS from the java.security provider list.","Add a smoke test that constructs the Kerberos Oid at startup."],"tags":["kerberos","gss-api","oid","jvm"],"backgroundTag":"module-init-failed","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}