apereo/cas
Documented errors, page 6 of 7. Back to apereo/cas
| Code / Message | Type | Severity | Tags |
|---|---|---|---|
| LDAP url cannot be empty/blank | validation | error | ldap, configuration, validation |
| No transaction found for | exception | error | oidc, vc, ticket, not-found |
| Provided refresh token | validation | error | oauth, refresh-token, client-mismatch, token-theft |
| JWK type is not supported | exception | error | jwk, jwt, signature, unsupported |
| OpenID provider requires authority hint(s) | exception | error | configuration, oidc-federation, authority-hints |
| Unable to locate [ ] in the message header | console | warning | websocket, stomp, qr-authentication, missing-header |
| Authentication request does not include the | console | warning | oidc, scope, id-token, configuration |
| Authentication throttling rate | http | warning | throttling, rate-limiting, threshold, authentication |
| No records found for user [username] | exception | error | jdbc, count-query, user-lookup |
| Token cannot be used before | exception | error | jwt, not-before-claim, clock-skew, claims-validation |
| Unknown authorization header type | exception | error | authorization, http-header, jwt, bearer-token |
| Unable to locate existing session from the current token | console | warning | webauthn, mfa, session-expired, webflow |
| Account removal is not verified for | exception | warning | webflow, mfa, account-removal, state |
| Redirect URI cannot contain a fragment | validation | error | oidc, dynamic-client-registration, validation, redirect-uri |
| Certificate subject does not match pattern | exception | error | x509, certificate, regex, authentication |
| Response [ ] is not recognized | console | warning | radius, authentication, unexpected-response |
| Account password must change for | exception | warning | authentication, rest, http-428, password-change |
| Account password on record for | exception | error | cassandra, authentication, bad-password |
| Principal resolution is unable to produce a result and will… | console | warning | principal-resolution, person-directory, attributes |
| Provided regular expression or IP/netmask | console | warning | ip-restriction, access-control, spring-security |
| Token does not belong to the assigned principal | exception | error | qr-authentication, jwt, principal-mismatch |
| Passwordless account | console | warning | passwordless, webflow, mfa |
| Unknown tenant for service ticket | exception | error | multitenant, service-ticket, tenant-mismatch |
| Authentication chain is empty as no authentications have… | console | warning | authentication, empty-state, webflow |
| Secret key for signing is not defined for | console | warning | signing, jwk, missing-config |
| Client IP [ ] is banned | console | warning | ip-reputation, banned-ip, adaptive-authentication, access-denied |
| JWT time claim is invalid | validation | error | jwt, claims, time, format |
| No assertion or its configuration was provided to validate… | console | warning | ws-federation, saml, signature, null-input |
| Password is null. | exception | error | authentication, password, validation |
| Passwordless account | console | warning | passwordless, webflow, user-input |
| Cannot get connection from pool to validate SPNEGO Token | exception | error | spnego, pool, timeout, authentication |
| Delegated authentication has failed with client | exception | error | delegated-authentication, pac4j, webflow, idp |
| Token encryption/signing is not enabled explicitly in the… | console | warning | configuration, crypto, cookie, mfa |
| Cannot find service provider metadata entity linked to | console | warning | saml, slo, metadata |
| No federation keys defined for entity | exception | error | oidc-federation, crypto, configuration |
| Passwordless account | console | warning | passwordless, webflow, delegated-authentication |
| Public key located from keystore for key id is undefined | exception | error | |
| Public key from endpoint for key id is undefined | exception | error | |
| Radius authentication failed for user | exception | error | radius, mfa, authentication, cas |
| Unable to determine google authenticator account | console | error | webflow, mfa, account, state |
| All CRLs retrieved have expired. Applying CRL expiration… | console | warning | x509, crl, expired, revocation-policy |
| No identifier found for this user profile: | exception | error | authentication, pac4j, principal, delegated |
| Could not locate an LDAP entry for [filter] and base DN… | exception | error | ldap, empty-result, configuration |
| JSON account repository file | console | warning | file, json, configuration, otp |
| SP SSODescriptor in the metadata has expired at | console | warning | saml, metadata, expired, spssodescriptor |
| Geo-locating an address by latitude/longitude | console | warning | geolocation, maxmind, unsupported-operation, lat-long |
| No authentication event has been recorded; CAS cannot… | console | warning | authentication, null-result, empty-state |
| Service ticket [ ] does not exist. | exception | error | tickets, service-ticket, ticket-registry |
| FailedLoginException | exception | error | redis, bad-credentials, authentication, cas |
| SNAPSHOT versions found in | console | error | gradle, version-catalog, dependency, snapshot |
| Provided client id [ ] cannot be matched against a service… | validation | warning | oauth, revocation, unregistered-client, service-registry |
| Submitting logout response to | console | warning | slo, logout, http, pac4j |
| Certificate path length | exception | error | x509, certificate, path-length, configuration |
| Service definition [ ] does not request a pairwise subject… | console | warning | oidc, pairwise, subject-type, config |
| Unknown CRL reason code. | exception | error | x509, crl, revocation, enum |
| No principal could be identified in the claim parameters… | console | warning | sts, claims, missing-principal, authentication |
| Actor token type is not supported | validation | error | oauth, token-exchange, actor-token, unsupported-value |
| Resource-set owner does not match the authenticated profile | validation | error | uma, resource-set, ownership, http-403 |
| The request is throttled as capacity is entirely consumed… | console | warning | bucket4j, rate-limiting, throttled |
| [username] not found with SQL query | exception | error | jdbc, sql, user-not-found |
| Could not authenticate forbidden account for | exception | error | authentication, rest, http-403, account-disabled |
| Could not authenticate locked account for | exception | error | authentication, rest, http-423, account-locked |
| Could not locate account for | exception | error | authentication, rest, http-404, user-not-found |
| Missing web authn token from the request | console | warning | webauthn, mfa, webflow, missing-parameter |
| No signature or configuration was provided to validate… | console | warning | ws-federation, saml, signature, null-input |
| Proof JWT algorithm does not match EC holder key | exception | error | jwt, algorithm, ec, key-mismatch, verifiable-credentials |
| AccountNotFoundException | exception | error | redis, account-not-found, authentication, cas |
| Base dn cannot be empty/blank for authenticated/anonymous… | validation | error | ldap, configuration, validation |
| No user can be accepted because none is defined | exception | error | java, authentication, configuration |
| Federation role [ ] is not supported for OpenID Provider | exception | error | configuration, oidc-federation, invalid-role |
| No claims are available to process | console | warning | sts, claims, empty-input |
| Client Credentials provided is not valid for registered… | exception | error | oauth2, client-secret, authentication |
| Failed to authenticate user | exception | error | jdbc, stored-procedure, authentication |
| Token [ ] has expired | console | warning | passwordless, token, expiration, jpa |
| User filter cannot be empty/blank for… | validation | error | ldap, configuration, validation |
| Request is not signed but should be | exception | error | saml, signature, authn-request, sp, security |
| Unable to authorize given token | console | warning | otp, mfa, registration, validation |
| Could not authenticate account for | exception | error | authentication, rest, http-401, bad-credentials |
| Failed to load configuration metadata | exception | error | javascript, http, actuator |
| Unable to login at this time | exception | error | authentication, time-window, json-resource, account-policy |
| No resource defined to prepare. | console | warning | null-argument, resource, logging |
| Unable to determine authentication from the request context | exception | error | aup, webflow, authentication |
| Trust anchor requires no authority hints | exception | error | configuration, oidc-federation, authority-hints |
| SAML2 attribute query profile is not enabled | console | warning | saml, saml-idp, attribute-query, soap, configuration |
| [username] not found. | exception | error | ldap, dn-resolution, user-not-found |
| Authentication did not produce a user profile for: | exception | error | authentication, pac4j, delegated, user-profile |
| Configuration file must be specified | console | warning | cli, configuration, properties |
| Skipping metadata [ ]; Either the resource cannot be… | console | warning | metadata, configuration, resource |
| Token has an invalid issuer that does not match | exception | error | jwt, issuer-mismatch, configuration, qr-authentication |
| Aborting since DenyRevocationPolicy is in effect. | exception | error | x509, revocation, policy, configuration |
| Could not authenticate expired account for | exception | error | authentication, rest, http-412, account-expired |
| Unable to determine entity id to fetch metadata via MDQ for | exception | error | saml, mdq, metadata, configuration, entity-id |
| CAS is configured to only accept pushed authorization… | console | error | oidc, par, http-403, authorization-request |
| JWT audience is invalid | validation | error | jwt, audience, claims, validation |
| Passwordless account | console | error | passwordless, ldap, attributes |
| Recaptcha response/token is missing from the request | console | warning | recaptcha, captcha, webflow, missing-parameter |
| JWT string claim is missing or invalid | validation | error | jwt, claims, validation, missing-claim |
| Proof JWT algorithm is invalid | exception | error | jwt, algorithm, unsigned-jwt, oidc, verifiable-credentials |
| Client IP [ ] is rejected for authentication | console | warning | adaptive-authentication, ip-rejection, access-control |
| [ ] is not readable. Check file permissions | console | warning | filesystem, permissions, service-registry |