slackhq/nebula
Documented errors, page 4 of 5. Back to slackhq/nebula
| Code / Message | Type | Severity | Tags |
|---|---|---|---|
| pkcs11 module gave us a nil CKA_PUBLIC_KEY_INFO, and… | exception | error | pkcs11, hsm, attribute-access-denied |
| stats.type was not understood | exception | error | config, stats, validation, nebula |
| config ` ` has invalid CIDR: . | validation | error | config, network, cidr, validation |
| could not enable TCP SACK | error_code | error | netstack, tcp, gvisor |
| sshd.listen can not use port 22 | validation | error | ssh, configuration, port-conflict |
ErrInitiateNotCalled initiate must be called before ProcessPacket for initiators | error_code | error | handshake, state-machine, ordering |
ErrUnknownState nebula state is invalid | error_code | error | lifecycle, state-machine, concurrency, go |
| failed to set tun mtu | exception | error | macos, darwin, mtu, ioctl, permissions |
| invalid integer | validation | error | asn1, p256, signature, encoding |
| nil header | error_code | error | header, nil-pointer, packet-encoding |
| already listening on port | validation | error | network, gvisor, netstack, listen, port-in-use |
| entry .route in tun.routes failed to parse | validation | error | config, validation, cidr |
ErrBadFormat bad wire format | error_code | error | parsing, asn1, certificate |
| error while reading ca-key | console | error | filesystem, file-read, ca-key, nebula-cert |
| -argon-iterations must be be greater than 0 and no more than | exception | error | crypto, argon2, iterations, bounds-check |
| config ` .interfaces` is invalid (type %T) | validation | error | config, validation, interfaces, allowlist |
| csum_start is zero | exception | error | network, tcp, offload, segmentation, packet-parsing |
| error while adding ca cert to pool | console | error | go, cli, pem, ca, certificate-parsing |
ErrInvalidPEMEd25519PrivateKeyBanner bytes did not contain a proper Ed25519 private key banner | error_code | error | pem, ed25519, key-parsing, config |
| invalid vpn addr for v1 handleHostQuery | exception | error | lighthouse, ipv6, cert-version |
| unsupported encryption algorithm | exception | error | encryption, algorithm-support, key-management, go |
| bind | exception | critical | udp, windows, bind, rio, address-in-use |
| stats.path should not be empty | validation | error | nebula, config, prometheus, stats, validation |
| unable to set SO_REUSEPORT | exception | error | udp, linux, so-reuseport, setsockopt |
ErrExpired certificate is expired | error_code | error | certificate, expiry, pkix |
| error while parsing ca-crt | console | error | |
| failed to get tun device link | exception | error | network, tun, linux, netlink |
| tunnel message counter is exhausted | exception | error | relay, tunnel, counter-exhaustion |
| unable to read pki.key file | validation | error | |
| add v6 filter | exception | error | windows, wfp, firewall, ipv6, network |
| calculated_remotes entry has invalid type: %T | validation | error | nebula, config, type-error, yaml, calculated-remotes |
| failed to open udp socket | exception | error | |
| unable to marshal unsafe network | exception | warning | certificate, marshalling, unsafe-networks |
| failed to get udp fd | exception | error | |
| host certificate is a CA certificate | validation | error | pki, certificate, config |
| invalid type: %T | validation | error | nebula, config, type-error, yaml, calculated-remotes |
| newTunFromFd not supported in Windows | exception | error | windows, tun, wintun, unsupported-feature |
| got an empty secret key | exception | error | pkcs11, hsm, ecdh, derive |
| invalid curve for PKCS#11 | error_code | error | cli, pkcs11, curve |
| - and - both set to , only one input may read from stdin | console | error | go, cli, stdin, flag-conflict |
| rule # ; proto was not understood; | validation | error | firewall, configuration, validation |
| code specified as [ ]. Support for 'code' will be dropped… | validation | error | go, firewall, config, deprecation |
| unknown pki.initiating_version | validation | error | pki, config, validation |
| WriteBatch: len(bufs)= | exception | error | udp, linux, writebatch, programming-error, argument-validation |
| entry .install in tun.unsafe_routes is not a boolean | validation | error | |
| failed to set the tun fd to non-blocking mode | exception | error | ios, tun, file-descriptor |
| no passphrase specified, remove -encrypt flag to write… | error_code | error | cli, passphrase, input-validation |
ErrSubtypeMismatch packet subtype does not match handshake machine subtype | error_code | warning | handshake, subtype, packet-parsing |
| newTunFromFd not supported in NetBSD | exception | error | netbsd, tun, unsupported, platform |
| rule # ; at least one of host, group, cidr, local_cidr… | validation | error | firewall, configuration, validation |
ErrEmptySignature empty signature | error_code | error | signature, certificate, signing |
ErrNoPeerStaticKey no peer static key was present | error_code | error | handshake, peer-key, nil-argument |
| rule # ; cidr did not parse; | validation | error | firewall, configuration, cidr, networking |
| self signed certificates must have IsCA set to true | error_code | error | pki, certificate, self-signed |
| error while getting public key | error_code | error | pkcs11, hsm, cli, keypair |
| invalid port | validation | error | nebula, config, port, validation, calculated-remotes |
| cannot open encrypted ca-key without passphrase | console | error | |
| error marshalling v2 certificate for handshake | error_code | error | pki, certificate, serialization |
| error while creating PKCS#11 client | error_code | error | cli, pkcs11, hsm |
| error while unmarshaling pki.cert | validation | error | pki, certificate, config |
| LocalAddr returned invalid IP address | exception | error | |
| no default config found at | validation | error | |
| %swas not a number; | validation | error | config, firewall, parse-error |
| unable to find host with relay | error_code | error | network, relay, hostmap, nebula |
| can not load the wintun driver | exception | critical | windows, tun, wintun, missing-dll |
| config ` .interfaces` values must all be the same… | validation | error | config, validation, interfaces, allowlist |
| failed to load config | exception | error | |
| newTun not supported in iOS | exception | error | ios, tun, unsupported-platform, network-extension |
| unable to bind to socket | exception | critical | udp, linux, bind, address-in-use, privileged-port |
| entry .via in tun.unsafe_routes is not a string or list of… | validation | error | |
ErrBadDetailsVpnAddr invalid packet, malformed detailsVpnAddr | error_code | warning | network, lighthouse, packet-parsing, nebula |
| tun.routes is not an array | validation | error | config, validation |
| winrio.Socket error | exception | error | udp, windows, winrio, socket-creation, rio |
| entry .weight in tun.unsafe_routes | validation | error | |
ErrUnknownIPVersion packet is an unknown ip version | error_code | warning | packet-parsing, ip-version, network |
| not a valid logging level | validation | error | logging, configuration, validation |
| rule # ; | validation | error | firewall, configuration, ports |
| Unexpected PacketConn: %T %#v | exception | error | |
| entry .route in tun.routes is not present | validation | error | config, validation |
| error while reading ca | console | error | go, cli, file-read, ca |
| no pki.cert path or PEM data provided | validation | critical | pki, config, nebula, missing-cert |
| failed to parse, should be an array of rules | validation | error | firewall, yaml, configuration, validation |
| entry .mtu in tun.routes is not an integer | validation | error | config, validation |
| certificate is valid before the signing certificate | validation | error | certificate, validity, ca-constraints |
| Empty configuration | validation | error | config, validation, go |
| created /dev/net/tun, but still failed | exception | error | linux, tun, kernel, permissions |
| entry .mtu in tun.unsafe_routes is not an integer | validation | error | |
| no cipher state available to encrypt | exception | error | noise, fips140, aesgcm, nil-state |
| no config files found at | validation | error | |
| only tcp is supported | validation | error | service, network, tcp, nebula |
| encoded Details was nil | exception | error | certificate, protobuf, unmarshal, missing-field |
ErrEmptyRawDetails empty rawDetails not allowed | error_code | error | certificate, marshal, uninitialized |
ErrRootExpired root certificate is expired | error_code | critical | certificate, expiry, pkix |
ErrBlockListed certificate is in the block list | error_code | critical | certificate, revocation, blocklist |
| failed to set tun address | exception | error | network, darwin, ipv6, ioctl, address-assignment |
| failed to set tun device mode | exception | error | netbsd, tun, ioctl, activate |
| no outside connection | validation | critical | network, config, udp, nebula, startup |
| failed to set default route MTU | exception | error | network, routing, tun, mtu |
| no certificate state | validation | critical | config, pki, certificates, nebula, startup |
| failed to get syscall conn for tun | exception | error | netbsd, tun, read, file-descriptor |