ErrLookup › gravitational/teleport
gravitational/teleport
The easiest, and most secure way to access and protect all of your infrastructure. · Go · 6,731 source files
Analyzed at 1283425b60 on 2026-09-02. 220 documented errors.
| Code / Message | Type | Severity | Tags |
|---|---|---|---|
| conn was closed | exception | error | grpc, connection-lifecycle, client |
| PIV is unavailable in current build | exception | error | hardware-keys, yubikey, build-config, cgo |
| distinguished name too large, refusing to parse | exception | warning | x509, parsing, input-validation |
| cannot route to empty target host | validation | error | routing, ssh, configuration |
| failed to delete a role that is still in use by a user, chec | exception | error | rbac, roles, referential-integrity |
| failed to delete a role that is still in use by a certificat | exception | error | rbac, roles, certificate-authority, referential-integrity |
| failed to delete a role that is still in use by an access li | exception | error | rbac, roles, access-lists, referential-integrity |
| region has no known FIPS endpoint | exception | error | aws, fips, iam-join, sts |
| unable to sign with requested key | exception | warning | keystore, hsm, kms, tls |
| credential not found | exception | warning | touchid, mfa, webauthn, macos |
| touch ID not available | exception | warning | touchid, macos, webauthn, availability |
| cannot fulfill credential parameters, only ES256 are support | exception | error | touchid, webauthn, es256, credential-parameters |
| user has only invalid WebAuthn registrations, consider a use | exception | error | webauthn, rpid, mfa, user-reset |
| you are using a security key that is not registered with Tel | exception | warning | webauthn, fido2, security-key, not-registered |
| device already holds a registered credential | exception | info | fido2, yubikey, webauthn, duplicate-registration |
| device not registered for passwordless | exception | info | fido2, passwordless, yubikey, webauthn |
| device cannot fulfill platform attachment requirement | exception | info | fido2, platform-authenticator, webauthn, attachment |
| device lacks resident key capabilities | exception | info | fido2, resident-key, yubikey, webauthn |
| device lacks PIN or user verification capabilities necessary | exception | info | fido2, user-verification, pin, webauthn |
| U2F devices cannot do passwordless | exception | info | fido2, u2f, passwordless, webauthn |
| no security keys found | exception | error | |
| all MFA devices failed | exception | error | |
| failed to open security keys | exception | error | |
| FIDO2 unavailable in current build | exception | error | |
| windows webauthn unavailable in current build | exception | error | |
| unexpected nil response from GetAssertion | exception | error | windows, webauthn, cgo, nil-pointer |
| unexpected nil response from MakeCredential | exception | error | windows, webauthn, cgo, nil-pointer |
| updater config file not found | exception | warning | autoupdate, config, go, sentinel-error |
| executable has unstable path | exception | warning | autoupdate, filesystem, go, sentinel-error |
| version is linked | exception | error | autoupdate, go, sentinel-error, filesystem |
| not supported on this platform | exception | warning | platform-support, systemd, autoupdate, sentinel-error |
| not available at this version | exception | info | feature-availability, version-gating, sentinel-error, touchid |
| no binaries available to link | exception | error | autoupdate, package-install, missing-files, sentinel-error |
| file present | exception | error | file-conflict, autoupdate, install-management, sentinel-error |
| not installed | exception | error | not-installed, autoupdate, cli, sentinel-error |
| baseURL is not defined | exception | info | environment-variable, autoupdate, managed-updates, sentinel-error |
| version check failed | exception | warning | version-check, corrupt-binary, autoupdate, sentinel-error |
| disconnect escape sequence detected | exception | info | interactive-session, escape-sequence, ssh, sentinel-error |
| internal buffer has grown too big | exception | error | buffer-overflow, backpressure, interactive-session, sentinel-error |
| elevated credential activation not implemented for linux | exception | error | devicetrust, tpm, linux, unimplemented |
| signChallenge not implemented for TPM devices | exception | error | |
| failed to open the TPM device, consider assigning the user t | exception | error | |
| signChallenge not implemented for TPM devices | exception | error | |
| sse event exceeded max size | exception | error | |
| app does not have SSO set up | exception | error | |
| cannot disable multi-factor authentication | validation | error | |
| tenant not found | exception | error | |
| invalid Graph API credentials | exception | error | |
| authentication was successful but application does not have | exception | error | |
| connection downgrade not allowed for URL: | validation | error | |
| stopped after 10 redirects | validation | error | |
| user input required | exception | error | |
| the request timed out. Try again or use streaming for long r | exception | error | |
| the inference provider rejected the request as invalid. Chec | exception | error | |
| the request was canceled | exception | error | |
| the inference provider rejected the request due to authentic | exception | error | |
| the inference provider rejected the request due to usage lim | exception | error | |
| teleport doesn't support the requested endpoint, please chec | exception | error | |
| the inference provider returned an unexpected response. Cont | exception | error | |
| unable to serve request due to an app configuration error. C | error_code | error | teleport, configuration, llm-proxy |
| unable to serve the request due to an internal error. Contac | error_code | error | teleport, internal-error, llm-proxy |
| tokens quota exceeded. Contact your Teleport administrator | error_code | warning | teleport, rate-limit, quota, llm-proxy |
| the inference provider returned an unexpected error. Contact | error_code | error | teleport, llm-proxy, unknown-error |
| session chunk already closed | error_code | error | teleport, app-session, session-recording, race-condition |
| failed to fetch MySQL version | exception | error | mysql, database, protocol, teleport |
| xsession was terminated | exception | error | teleport, desktop-access, xsession, process-crash |
| failed to create decoder | exception | error | rdp, cgo, decoder, desktop-access, teleport |
| decoder not initialized | exception | error | rdp, decoder, nil-pointer, desktop-access |
| invalid resize dimensions | validation | warning | rdp, decoder, validation, desktop-access |
| decoder has no pixel format | exception | error | rdp, desktop, cgo, video-decoding |
| failed to resize crop region | exception | error | rdp, desktop, cgo, video-decoding |
| the real rdpclient.Client implementation was not included in | exception | error | rdp, build-tags, desktop, stub |
| unexpected message type | error_code | info | tdp, mfa, protocol |
| decoded unknown TDPB message | error_code | warning | tdpb, protocol, version-skew |
| message is TDP, not TDPB | error_code | warning | tdpb, tdp, protocol-upgrade |
| no more IDs available | exception | error | x11, xvfb, resource-exhaustion |
| no Access Graph fetchers | error_code | info | discovery, aws, azure, access-graph, configuration |
| TAG feature is not enabled | error_code | warning | licensing, feature-flag, access-graph, discovery |
| all fetched nodes already enrolled | error_code | info | discovery, gcp, empty-result |
| User logged in error | error_code | warning | host-users, linux, session-conflict |
| user not managed by teleport | error_code | warning | host-users, user-management, linux |
| managed host users can not be converted to or from a static | error_code | warning | host-users, static-host-users, user-management |
| agent forwarding channel already open | exception | error | ssh, agent-forwarding, duplicate-registration |
| nil certificate override | validation | error | subca, validation, config, x509 |
| invalid public key | validation | error | subca, validation, public-key, x509 |
| certificate or public key required | validation | error | subca, validation, config |
| certificate required | validation | error | subca, validation, x509, config |
| chain not allowed with an empty certificate | validation | error | x509, certificate, configuration, validation |
| override certificate should not be included in chain | validation | error | x509, certificate, configuration, chain-of-trust |
| not a CA certificate (IsCA=false) | validation | error | x509, certificate, ca, validation |
| basic constraints not valid (BasicConstraintsValid=false) | validation | error | x509, certificate, ca, validation |
| missing KeyUsage keyCertSign | validation | error | x509, certificate, keyusage, validation |
| missing KeyUsage cRLSign | validation | error | x509, certificate, keyusage, crl |
| NotBefore > NotAfter | validation | error | x509, certificate, validity, validation |
| PID files are not supported on Windows | exception | warning | windows, pidfile, platform-limitation |
| interrupted | exception | info | prompt, interactive, user-cancellation, signal |
| canceled | exception | info | prompt, interactive, user-cancellation |
| VNet is already running | exception | warning | macos, vnet, daemon, xpc |
| either identifier or team identifier is missing in code sign | exception | error | macos, code-signing, vnet, security |
| XPC connection interrupted | exception | error | macos, xpc, vnet, network |
| code signing requirement failed | exception | error | macos, xpc, code-signing, vnet |
| XPC connection invalid | exception | error | macos, xpc, launchd, vnet |
| the background item was not enabled within the timeout | exception | error | macos, login-items, timeout, vnet |
| could not connect to the VNet daemon within the timeout | exception | error | macos, xpc, timeout, vnet, daemon |
| an unknown error has occurred | exception | warning | desktop-access, websocket, protocol |
| proto: ContextUser: illegal tag %d (wire type %d) | validation | error | protobuf, deserialization, grpc, data-corruption |
| proto: Passwordless: wiretype end group for non-group | validation | error | protobuf, grpc, deserialization, wire-format |
| proto: Passwordless: illegal tag %d (wire type %d) | validation | error | protobuf, grpc, deserialization, wire-format |
| proto: CreateAuthenticateChallengeRequest: wiretype end grou | validation | error | protobuf, grpc, deserialization, wire-format |
| proto: CreateAuthenticateChallengeRequest: illegal tag %d (w | validation | error | protobuf, grpc, deserialization, version-skew |
| proto: wrong wireType = %d for field UserCredentials | validation | error | protobuf, grpc, oneof, wire-format |
| proto: wrong wireType = %d for field RecoveryStartTokenID | validation | error | protobuf, grpc, wire-format, version-skew |
| proto: wrong wireType = %d for field ContextUser | validation | error | protobuf, grpc, oneof, wire-format |
| proto: wrong wireType = %d for field Passwordless | validation | error | protobuf, grpc, oneof, wire-format |
| proto: wrong wireType = %d for field MFARequiredCheck | validation | error | protobuf, grpc, wire-format, version-skew |
| proto: wrong wireType = %d for field ChallengeExtensions | validation | error | protobuf, grpc, wire-format, version-skew |
| proto: wrong wireType = %d for field SSOClientRedirectURL | validation | error | protobuf, grpc, wire-format, deserialization |
| proto: wrong wireType = %d for field ProxyAddress | validation | error | protobuf, grpc, wire-format, deserialization |
| proto: wrong wireType = %d for field BrowserMFATSHRedirectUR | validation | error | protobuf, grpc, wire-format, deserialization |
| proto: wrong wireType = %d for field BrowserMFARequestID | validation | error | protobuf, grpc, wire-format, deserialization |
| proto: CreatePrivilegeTokenRequest: wiretype end group for n | validation | error | protobuf, wire-format, malformed-data, deserialization |
| proto: CreatePrivilegeTokenRequest: illegal tag %d (wire typ | validation | error | protobuf, wire-format, malformed-data, deserialization |
| proto: wrong wireType = %d for field ExistingMFAResponse | validation | error | protobuf, grpc, wire-format, deserialization, mfa |
| proto: CreateRegisterChallengeRequest: wiretype end group fo | validation | error | protobuf, wire-format, malformed-data, deserialization |
| proto: CreateRegisterChallengeRequest: illegal tag %d (wire | validation | error | protobuf, wire-format, malformed-data, deserialization |
| proto: wrong wireType = %d for field TokenID | validation | error | protobuf, grpc, wire-format, deserialization |
| proto: wrong wireType = %d for field DeviceType | validation | error | protobuf, grpc, wire-format, version-skew, teleport |
| proto: wrong wireType = %d for field DeviceUsage | validation | error | protobuf, grpc, wire-format, version-skew, teleport |
| proto: IdentityCenterAccount: wiretype end group for non-gro | validation | error | protobuf, grpc, wire-format, data-corruption, teleport |
| proto: IdentityCenterAccount: illegal tag %d (wire type %d) | validation | error | protobuf, grpc, wire-format, data-corruption, teleport |
| proto: wrong wireType = %d for field ID | validation | error | protobuf, grpc, wire-format, version-skew, teleport |
| proto: wrong wireType = %d for field ARN | validation | error | protobuf, grpc, wire-format, version-skew, teleport |
| proto: wrong wireType = %d for field AccountName | validation | error | protobuf, grpc, wire-format, version-skew, teleport |
| proto: wrong wireType = %d for field Description | validation | error | protobuf, grpc, wire-format, version-skew, teleport |
| proto: IdentityCenterPermissionSet: wiretype end group for n | validation | error | protobuf, grpc, wire-format, data-corruption, teleport |
| proto: IdentityCenterPermissionSet: illegal tag %d (wire typ | validation | error | |
| proto: wrong wireType = %d for field Name | validation | error | |
| proto: IdentityCenterAccountAssignment: wiretype end group f | validation | error | |
| proto: IdentityCenterAccountAssignment: illegal tag %d (wire | validation | error | |
| proto: wrong wireType = %d for field Kind | validation | error | |
| proto: wrong wireType = %d for field SubKind | validation | error | |
| proto: wrong wireType = %d for field Version | validation | error | |
| proto: wrong wireType = %d for field Metadata | validation | error | |
| unsupported json type %T | exception | error | |
| too large: %v | validation | warning | grpc, configuration, integer-overflow, env-var |
| unhandled size name: %v | validation | warning | grpc, configuration, env-var, parsing |
| malformed RDNs: %w | validation | error | x509, parsing, distinguished-name, configuration |
| repeated attributeType %q, remaining tokens: %s | validation | error | x509, distinguished-name, parsing, validation |
| multi-valued RDN must refer to the same attribute, but found | validation | error | x509, distinguished-name, parsing, rfc4514 |
| not enough tokens to parse AttributeTypeValue, remaining tok | validation | error | x509, distinguished-name, parsing, truncated-input |
| invalid attributeType (bad character set): %q | validation | error | x509, distinguished-name, parsing, validation |
| unknown attributeType %q, remaining tokens: %s | validation | error | x509, distinguished-name, parsing, configuration |
| cannot parse OID component %q as int, OID=%q: %w | validation | error | x509, oid, asn1, parsing |
| found %s instead of %s, remaining tokens: %s | validation | error | x509, distinguished-name, parsing, tokenizer |
| hexstring not supported: %s | validation | error | x509, distinguished-name, parser, unsupported-feature |
| want attributeType, found %q: %s | validation | error | x509, distinguished-name, parser, syntax |
| want attributeType or '=', found %q: %s | validation | error | x509, distinguished-name, parser, syntax |
| want '=' attributeValue, found %q: %s | validation | error | x509, distinguished-name, parser, syntax |
| special character %q not quoted: %s | validation | error | x509, distinguished-name, escaping, parser |
| unexpected escaped character %q: %s | validation | error | x509, distinguished-name, escaping, parser |
| want '+' or ',', found %q: %s | validation | error | x509, distinguished-name, parser, syntax |
| want attributeType, found EOF | validation | error | x509, distinguished-name, parser, truncated-input |
| want attributeType or '=', found EOF | validation | error | x509, distinguished-name, parser, truncated-input |
| want '=' attributeValue, found EOF | validation | error | x509, distinguished-name, parser, truncated-input |
| want escaped character, found EOF | validation | error | parsing, ldap, dn, eof |
| want closing quote, found EOF | validation | error | parsing, ldap, dn, quoting |
| found EOF (state=%d) | validation | error | parsing, ldap, dn, eof |
| error in data JSON: %w | validation | error | json, accessgraph, merge, validation |
| error in patch JSON: %w | validation | error | json, accessgraph, merge, validation |
| error writing merged JSON: %w | validation | error | json, accessgraph, marshal, merge |
| PKCS11 HSM support requires a license with the HSM feature e | error_code | critical | licensing, hsm, pkcs11, startup |
| GCP KMS support requires a license with the HSM feature enab | error_code | critical | licensing, hsm, gcp-kms, startup |
| AWS KMS support requires a license with the HSM feature enab | error_code | critical | licensing, hsm, aws-kms, startup |
| moderated sessions: %w | error_code | error | licensing, moderated-sessions, session-tracker, enterprise |
| unknown integration subkind: %s | error_code | error | teleport, integrations, unhandled-case |
| cannot fulfill authenticator attachment %q | error_code | error | webauthn, touchid, macos |
| cred required for %q ceremony | error_code | error | webauthn, touchid, attestation |
| picker returned invalid credential: %#v | error_code | error | touchid, macos, pointer-identity |
| %v: %v | error_code | error | touchid, macos, error-wrapping |
| %v: status %d | error_code | error | touchid, macos, error-wrapping, status-code |
| no credentials for user %q | error_code | error | webauthn, fido2, hardware-keys |
| prompt returned invalid credential: %#v | error_code | error | webauthn, fido2, pointer-identity |
| max retry attempts reached: %w | error_code | error | webauthn, fido2, retry-exhausted, hardware-keys |
| prompt returned invalid credential: %#v | error_code | error | webauthn, prompt, input-validation |
| webauthn error code %v and syscall err: %v | error_code | error | windows, webauthn, syscall, hardware, mfa |
| webauthn error code %v | error_code | warning | windows, webauthn, syscall, mfa, diagnostics |
| webauthn error code %v: %v | error_code | error | |
| kubernetes cluster %q is not registered or is offline | error_code | error | |
| failed to retrieve stdout mode: %w | error_code | error | windows, terminal, console-api, io |
| failed to set stdout mode: %w | error_code | error | windows, terminal, vt100, console-api |
| failed to set stdin mode: %w | error_code | error | windows, terminal, console-api, stdin, raw-mode |
| a tncon session is already active | error_code | error | windows, terminal, singleton, concurrency, lifecycle |
| %q is not a valid x509 certificate (%w) and can't be read as | validation | error | |
| file %q contains an invalid x509 certificate: %w | validation | error | |
| public key representation too small (%v bytes) | error_code | error | |
| public key representation has unexpected length (%v bytes) | error_code | error | |
| public key representation starts with unexpected byte (%#x v | error_code | error | |
| unexpected jamf version string: %q | error_code | error | |
| err.Error() | http | error | |
| respErr.Error() | http | error | |
| Internal Server Error | http | error | |
| http.StatusText(status) | http | error | |
| Internal Server Error | http | error | |
| Internal Server Error | http | error | |
| http.StatusText(code) | http | error | |
| deny.body | http | error | |
| http.StatusText(code) | http | error | |
| http.StatusText(code) | http | error | |
| http.StatusText(code) | http | error | |
| authclient.ErrNoMFADevices.Error() | http | error | |
| http.StatusText(code) | http | error | |
| A trusted device is required to access this resource but thi | http | error | |
| err.Error() | http | error | |
| err.Error() | http | error | |
| http.StatusText(trace.ErrorToCode(err)) | http | error | |
| peer certificate is missing | error_code | error | |
| Failed to get AWS identity when checking a database created | console | error | |
| The database agent's identity and discovered database have d | console | error | |
| Failed to get Azure subscription IDs when checking a databas | console | error | |
| The discovered database is in a subscription that the databa | console | error |