apereo/cas
Documented errors, page 4 of 7. Back to apereo/cas
| Code / Message | Type | Severity | Tags |
|---|---|---|---|
| Could not extract registered services from request body | http | error | rest, http-400, import, empty-body |
| Principal is null, the processing of the SPNEGO Token failed | exception | error | spnego, kerberos, jcifs, authentication |
| Resource ID already exists in namespace . | exception | error | javascript, duplicate-resource-id, validation |
screen.oidc.issuer.invalid The issuer URL is invalid and does not match the CAS server issuer URL. | http | error | oidc, logout, id-token, http-400, client-id-mismatch |
| Found certificate attribute | console | warning | x509, crl, ldap, ldaptive, binary-attribute |
| No credentials are provided or extracted to authenticate… | exception | error | rest, cas, credentials, authentication |
| Logout request is not issued by a trusted issuer | console | warning | oidc, logout, issuer, trust |
| Principal resolution handled by | console | warning | authentication, principal-resolution, attributes |
| Provider: [ ] does not support Algorithm: [ ] | console | info | jasypt, jce, crypto, provider |
| Required NameID format | console | warning | saml, saml-idp, nameid, metadata, authn-request |
| Audience [ ] is invalid where the expected audience should… | console | warning | ws-federation, audience-mismatch, relying-party, validation |
| Cannot validate authentication for: [login] | exception | error | mfa, inwebo, authentication, failed-login |
| Could not authenticate forbidden account for | exception | error | syncope, account-disabled, authentication, cas |
| Keystore file, password or alias assigned to the realm are… | console | warning | sts, keystore, configuration, crypto |
| No valid JSON web keys used for encryption can be found | console | error | oidc, jwks, encryption, invalid-key-material |
| Private key located from keystore for key id is undefined | exception | error | |
| No groovy script cache manager is available for attribute… | console | warning | groovy, scripted-attributes, cache-manager, attribute-definition, empty-result |
| Ticket is issued before the allowed drift. Issued on | console | warning | wsfederation, clock-skew, token-expired, sso |
| Unable to accept certificate | exception | error | oauth2, x509, mtls, certificate |
| Unable to resolve SP ACS URL for AuthnRequest construction | exception | error | saml, unsolicited-sso, acs-url, configuration |
| Could not grant service ticket | console | warning | cas, webflow, service-ticket, ticket-registry |
| Individual claims requested by OpenID scopes are forced to… | console | warning | oidc, spec-violation, id-token, configuration |
| Unable to determine the [WA] parameter | exception | error | ws-federation, http, sso |
| Client name for [ ] is set to a generated value of [ ]… | console | warning | pac4j, delegated-authentication, configuration, naming |
| No registered devices for multifactor authentication could… | console | warning | password-management, mfa, device-registration |
| Service [ ] is not allowed to use SSO. | exception | error | ws-federation, unauthorized-sso, service-registry, access-strategy |
| Service [ ] with client id [ ] is configured to encrypt… | console | error | oidc, jwks, encryption, cache-miss |
| Unable to locate user based on the given user handle | console | warning | webauthn, mfa, user-handle, credential-repository |
| Unable to verify QR code | exception | error | qr-authentication, token-validation, authentication |
| Unsupported event [ ] for service replication | console | warning | events, replication, service-registry, streaming |
| Attribute repository caching is disabled | console | warning | caching, attribute-repository, configuration |
| Could not update the LDAP entry's password for [filter] and… | exception | critical | ldap, password-policy, write-failure |
| Could not validate assertion via the provided token | exception | error | ws-federation, saml-assertion, signature-verification |
| No username parameter is provided | console | warning | password-management, missing-parameter, webflow |
| All CRL entries have been revoked. Rejecting the first entry | exception | error | x509, crl, revoked-certificate, revocation |
| Assertion will skip assigning/generating a nameId based on… | console | warning | saml, saml-idp, nameid, service-config |
| Invalid cookie . Required user-agent does not match | exception | warning | cookie, user-agent, security |
| The access token is invalid, expired, has an invalid grant… | console | error | oidc, oauth2, access-token, verifiable-credentials |
| Unknown realm: [ ] | exception | error | sts, realm, uri, sts-exception |
| [e.getMessage()] | exception | error | jdbc, database, authentication, bind-mode |
| SPNEGO Authorization header is not found under | console | warning | spnego, http-header, kerberos, sso |
| Unable to locate registration record for | exception | error | webauthn, mfa, account-not-found, registration |
| Invalid cookie . Required remote address does not match | exception | error | |
| Missing surrogate username in credential | validation | error | surrogate, impersonation, missing-value |
| No registered service is found to match | console | warning | themes, service-registry, access-control, fallback |
| Secret key for encryption defined under | console | warning | encryption, base64, invalid-config-value |
| Unable to obtain a bucket for | console | warning | bucket4j, rate-limiting, throttle |
| Could not extract and identify credentials | exception | error | ws-federation, credential-extraction, identifier-mismatch, saml-assertion |
| Could not locate LDAP attribute | console | warning | ldap, attribute-not-found, password-management |
| Current Java version | console | error | gradle, java-version, build, environment |
| Dialect name must be a fully qualified class name… | console | warning | hibernate, ddl, cli, dialect |
| failoverOnException enabled -- trying next server. | console | warning | radius, failover, network |
| logger.warn(LOG_MESSAGE_SUMMARIZER.summarizeStackTrace(messa… | console | info | logging, stack-trace, summarization |
| NTLM not allowed | exception | error | spnego, kerberos, ntlm, authentication |
| Password has expired | exception | warning | jdbc, authentication, password-expired |
| Password reset token could not be verified to determine… | validation | error | password-reset, token-validation, jwt |
| Reaching Duo has failed with error | console | warning | duo, mfa, network, connectivity |
| Unable to resolve the encryption [public] key for entity id | console | error | saml, saml-idp, encryption, metadata, x509 |
| Unauthorized account removal attempt | exception | error | gauth, webflow, mfa, authorization |
| Invalid cookie . Required fields are empty | exception | error | |
missing_access_token Access token cannot be found in the request | error_code | warning | oauth2, rfc7662, missing-parameter, introspection |
| Principal id attribute is not found for [principalAttr] | exception | error | ldap, principal, configuration |
| Subject token type is not supported | validation | error | oauth2, token-exchange, unsupported |
| Ticket is issued after the allowed drift. Retrieved on | console | warning | wsfederation, clock-skew, token-validation, sso |
UNAUTHORIZED_SERVICE_PROXY Proxying is not allowed for registered service | exception | error | proxy-ticket, registered-service, unauthorized |
| No recipient is provided with a valid email/phone for | http | warning | password-reset, rest-endpoint, email, missing-attribute |
| Retrieved realm from CN of SAML assertion certificate | console | warning | saml, sts, certificate, realm-mismatch |
| The authentication request is not recognized | exception | error | ws-federation, http, invalid-parameter-value |
| Unable to determine google authenticator token credential | console | error | webflow, mfa, credential, binding |
| Endpoint for is not available or does not define a binding… | exception | error | saml, idp, binding, metadata, endpoint |
| No expiration policy was found for ticket state | console | warning | cas, expiration-policy, misconfiguration, ttl |
| No service authentication request is available at | exception | warning | cas, login, webflow, missing-parameter |
| Unable to determine version for dependency | console | error | gradle, bom, version-catalog, dependency-resolution |
| Unable to locate a matching service definition from file | console | warning | watcher, service-registry, cache |
| Authorization of OTP token | exception | warning | otp, authentication, mfa, login-failure |
| Configuration file format | console | warning | cli, configuration, file-format |
| Could not determine authentication from the request context | console | warning | mfa, webflow, authentication, trusted-devices |
| Duo Security universal prompt authentication has failed | exception | error | duo, mfa, universal-prompt, failed-login |
| Invalid token: | exception | error | oauth2, refresh-token, ticket-registry |
| No wctx parameter is found | exception | error | ws-federation, missing-parameter, wctx, request-validation |
| Service Management: Unauthorized Service Access. Service | exception | error | service-registry, access-strategy, unauthorized-service |
| Attribute query ticket | console | warning | saml, ticket-expired, attribute-query |
| Entity descriptor in the metadata has expired at | console | warning | saml, metadata, expired, validuntil |
| No providerId parameter given in unsolicited SSO… | console | error | saml, missing-parameter, unsolicited-sso, cas |
| Unable to encrypt assertion for | exception | error | saml, encryption, assertion, metadata, sp |
| Access Denied for user | http | warning | throttling, rate-limit, http-423, access-denied, brute-force |
| Expired or invalid certificate in metadata for | exception | error | saml, metadata, certificate, x509, expired-certificate |
invalid_client Unable to locate and extract credentials from the request | error_code | error | oauth2, http-401, client-authentication, introspection |
| No registered devices for multifactor authentication could… | console | warning | mfa, password-reset, webflow, security |
| Password cannot be blank | validation | error | ldap, validation, empty-credentials |
| Proof JWT algorithm does not match RSA holder key | exception | error | jwt, algorithm, rsa, key-mismatch, verifiable-credentials |
| Unable to locate registered service for clientId | validation | warning | oauth2, service-registry, client-not-registered, configuration |
| Google Authenticator one-time token account… | console | warning | gauth, crypto, security, configuration |
| Invalid cookie Required remote address does not match | exception | error | |
| Multiple principal values are not allowed: [principalAttr] | exception | error | ldap, authentication, configuration |
| No security token could be retrieved for service | exception | error | ws-federation, security-token, unauthorized-service, sts |
| subordinate directory | console | error | filesystem, configuration, startup |
| The resulting authentication attempt has not recorded any… | console | error | authentication, handler-unsupported-credential, misconfiguration |
| YubiKey validation failed: | exception | error | yubikey, network, verification, wrapped-exception |
| Missing parameter wresult | validation | error | ws-federation, saml-token, http |