apereo/cas
Documented errors, page 2 of 7. Back to apereo/cas
| Code / Message | Type | Severity | Tags |
|---|---|---|---|
| Validation attempt for principal is throttled | exception | warning | mfa, rate-limiting, throttling, security |
| warn(logger, getMessage(throwable), throwable) | console | warning | cas, ticket-registry, cleanup, logging |
| Could not decode provided CertificateFile: | exception | error | spring, saml, x509, certificate-chain, file-read |
| Token [ ] has exceeded the maximum number of attempts [ ] | console | warning | mfa, gauth, otp, rate-limit |
| ACR [ ] is not defined as a supported ACR in CAS… | console | warning | oidc, acr, mfa, configuration |
| cannot be found in the registry | exception | error | gauth, otp, account-not-found, mfa |
| Found removable encoded ticket | console | warning | cas, ticket-registry, encryption, configuration-drift |
| Invalid response format received from Duo | exception | error | duo, mfa, api-response, http-client |
| Unable to use 'none' as ID token encryption algorithm | exception | error | oidc, configuration, encryption, id-token |
| Unable to use 'none' as ID token signing algorithm | exception | error | oidc, configuration, signing, id-token |
| Custom theme [ ] for service [ ] cannot be located. Falling… | console | warning | themes, resource-not-found, service-registry, fallback |
| Invalid cookie . Required fields are empty | exception | warning | cookie, session, security, invalid-cookie |
| No value could be retrieved from the header | console | info | spnego, remote-ip, proxy, http-header |
| No custom principal attribute was provided by the client | console | warning | pac4j, delegated-authentication, principal-attribute, attribute-release |
| No ticket definition could be found in the catalog to match | console | warning | dynamodb, ticket-registry, ticket-catalog, null-return |
| Interrupt response has blocked the authentication flow | console | error | interrupt, webflow, unauthorized |
| Located claim [ ] mapped to attribute [ ], yet resolved… | console | warning | oidc, attributes, claim-mapping, config |
| Not all requested multifactor providers could be found… | exception | error | mfa, multifactor, provider-absent, misconfiguration, trigger |
unauthorized_client Client is not allowed to use the | error_code | error | oauth, response-type, unauthorized-client, service-registry |
| Ticket created [ ] second(s) in the future. Check time… | console | warning | cas, clock-skew, distributed-systems, ntp |
| Client [ ] is rejected for authentication based on country… | console | warning | adaptive-authentication, geoip, access-denied, security-policy |
| Realm [ ] doesn't match with configured realm [ ] | console | warning | sts, claims, realm-mismatch, ws-security |
| Registered OpenID Connect relying party does not support… | exception | error | oidc, ciba, configuration, grant-type |
| Unable to accept cookie for authentication | exception | error | authentication, cookie, decryption, failed-login |
| Unable to match required address | exception | error | |
| [ ] Caused by: [ ] | console | warning | rest, authentication, http-401, credentials |
| Account password must change for | exception | warning | syncope, password-expired, authentication, cas |
| LoggingUtils.warn(LOGGER, e); | console | warning | functional, error-handling, exception-wrapper |
| Unable to find supported NameID format for service | exception | error | saml, nameid, single-logout, service-config |
| Denied | exception | error | authentication, registered-service, sso, authorization |
| No expiration policy could be found by the name | console | warning | cas, expiration-policy, lookup-failure, misconfiguration |
| Registered service with id | console | warning | config, registered-service, validation |
| Response type not authorized for service | validation | warning | oauth, response-type, authorization-code, service-definition |
| Signing credentials for validation could not be resolved… | exception | error | saml, signature-validation, sp-metadata, credentials |
| Unable to detect the authentication principal for | exception | error | authentication, rest, json-deserialization, principal-resolution |
| User Agent header [ ] is empty, or no browsers are supported | console | warning | spnego, kerberos, user-agent, webflow |
| Rest endpoint returned an unknown status code | exception | error | authentication, rest, unexpected-http-status, fail-safe |
| User Agent header [ ] is not supported in the list of… | console | warning | spnego, user-agent, browser-detection, configuration |
| Code verification does not match the challenge assigned to: | exception | error | oauth2, pkce, credentials |
| Backchannel token delivery mode cannot grant access tokens | console | warning | oidc, ciba, token, configuration |
| Dn format cannot be empty/blank for authentication | validation | error | ldap, configuration, cas |
| Principal is unauthorized to authenticate as | exception | error | surrogate, impersonation, authorization |
| <script exception> | exception | error | |
| Unable to establish authentication using provided… | exception | error | rest, cas, basic-auth, authentication-failed |
| Ignoring malformed request | validation | warning | oauth2, revocation, malformed-request, validation |
| <policy status exception> | exception | error | http, authentication-policy, rest |
| Provided authentication result is undefined to evaluate for… | console | warning | authentication, principal, sso |
| DN resolution failed. | exception | error | ldap, authentication, user-not-found, dn-resolution |
| Adaptive authentication policy does not allow this request… | exception | warning | authentication, adaptive-policy, webflow |
| Could not authenticate account for | exception | error | syncope, failed-login, bad-credentials, authentication, cas |
| No metadata resolvers could be configured for service with… | exception | error | saml, metadata, registered-service, resolver, config |
| No state could be found to determine session state | exception | error | ws-federation, sso, cookie, delegated-authentication |
| Found multiple values for id attribute | console | warning | wsfederation, principal-resolution, attributes, sso |
| Service is not found or is disabled in the service registry. | exception | error | unauthorized-service, service-registry, access-strategy |
| Unable to extract credentials for multifactor authentication | exception | error | rest, mfa, authentication, credentials |
| Unable to use 'none' as user-info encryption algorithm | exception | error | oidc, configuration, misconfiguration, encryption |
| Service ticket [ ] issued for service [ ] has already… | console | error | cas, service-ticket, one-time-use, protocol-violation |
| Logout request is not signed but should be for service | exception | error | saml, single-logout, signature-validation, service-config |
| No [ ] key could be found for issuer [ ] | console | error | oidc, jwks, signing, cache-miss |
| Pattern cannot be null/blank | console | warning | regex, configuration, null-value |
| Found configuration property as a Map | console | warning | configuration, metadata, build-time, map |
| No expiration policy was found for ticket state | console | warning | cas, expiration-policy, misconfiguration, fallback |
| Password does not match value on record. | exception | error | jdbc, authentication, password-compare |
| Token encryption/signing is not enabled explicitly in the… | console | warning | configuration, crypto, tokens, jwt |
| Unable to locate principal for token | exception | error | mfa, tickets, token-validation, security |
| Could not determine the hash algorithm for token | exception | error | oauth2, jwt, hash, algorithm |
| Metadata artifact at | console | warning | saml, idp, metadata, empty-file, filesystem |
| OTP format is invalid | exception | error | yubikey, mfa, otp, validation |
| Requested grant type | validation | warning | oauth, grant-type, password-grant, service-definition |
| Authenticated profile does not carry the UMA protection… | exception | error | uma, authorization, profile, missing-role |
| Service definition [ ] is undefined or it's not an OpenId… | console | warning | oidc, pairwise, registered-service, type-mismatch |
| Skipped registration of | console | warning | saml, metadata, service-registry, configuration |
| Request does not specify a user-agent | exception | error | cookie, http-headers, user-agent |
| Unable to detect authenticated user profile for prompt-less… | console | warning | oidc, sso, session, redirect |
| Invalid ticket type [blank] specified | exception | error | |
| Located [ ] S3 object(s) from bucket [ ] | console | error | aws, s3, duplicate-objects, metadata, illegalargument |
| Authentication request was denied from the provider | exception | error | sso, delegated-authentication, pac4j, service-authorization |
| Configured login config for CAS under | console | warning | jcifs, spnego, jaas, configuration-conflict |
| Failed to establish a connection ldap and search. | exception | error | ldap, crl, x509, revocation, network |
| Throttled submission | console | warning | throttling, rate-limiting, authentication, brute-force |
| Unable to verify provided user code | exception | error | oidc, ciba, user-code, authentication |
| AccountLockedException | exception | error | authentication, redis, account-locked |
| Client id [ ] in logout request does not match client id [… | console | error | oidc, logout, client-id, http-400, id-token |
| Dynamic client registration mode is not configured as… | console | warning | oidc, dynamic-client-registration, configuration, access-token |
| MultifactorAuthenticationProviderAbsentException | exception | critical | mfa, radius, configuration, cas |
| Recovering From Exception thrown by | console | warning | attribute-repository, person-attribute-dao, graceful-degradation, jdbc, ldap |
| Webflow execution key is invalid | exception | error | |
| Client Credentials provided is not valid for service: | exception | error | oauth2, pkce, client-authentication |
| Theme [ ] for service [ ] cannot be located | console | warning | themes, message-source, resource-not-found, classpath |
| Cannot authorize principal | exception | error | authorization, access-strategy, registered-service, principal |
| No ClientInfo could be found. Returning empty ClientInfo… | console | warning | audit, client-info, thread-local, inspektr |
| [ ] is configured to use [ ] but it does not support [ ]… | console | warning | authentication, principal-resolution, spring-config |
| No authentication found for ticket | exception | error | service-ticket, ticket-registry, webflow |
| Security exception while attempting to if the target class | console | warning | reflection, security, cache, security-manager |
| Unable to identify the public key from the signing… | exception | error | saml, signing, credentials, public-key, keystore |
| Unable to match required remote address | exception | warning | cookie, client-info, filter-chain, security |
| Could not locate metadata for | console | warning | saml, idp, attributes, metadata, entity-not-found |
| JWKS cannot contain expressions | validation | critical | oidc, jwks, expression-injection, security |
| CAS cannot use [ ] as the principal attribute id, since the… | console | warning | pac4j, delegated-authentication, principal-attribute, attribute-release |
| out.warn(ASCII_ART_LOGGER_MARKER, message) | console | info | logging, startup, ascii-art, warning-banner |