spring-projects/spring-security · error · IllegalStateException
Unable to instantiate Oid:
Error message
Unable to instantiate Oid:
What it means
KerberosMultiTier.createOid wraps GSSException from `new Oid(oid)` in an IllegalStateException. The static KERBEROS_OID constant initializes at class load; if the hard-coded Kerberos V5 OID string is rejected by the JGSS provider, class initialization fails.
Solutions
- Use a standard Oracle/OpenJDK JGSS provider that supports the Kerberos V5 OID.
- Check java.security provider ordering does not remove the SunJGSS provider.
- Inspect the GSSException cause for provider-specific details.
- As a workaround, construct the Oid manually in your own code to test provider support.
Defensive patterns
Strategy: try-catch
Validate before calling
try {
new Oid("1.2.840.113554.1.2.2");
} catch (GSSException e) {
throw new IllegalStateException("JGSS provider lacks Kerberos V5 OID support", e);
} Try / catch
try {
Class.forName("org.springframework.security.kerberos.authentication.KerberosMultiTier");
} catch (Throwable t) {
LOG.error("JGSS provider cannot init KerberosMultiTier", t);
} Prevention
- Deploy on standard JDKs with the SunJGSS provider enabled.
- Do not remove SunJGSS from the java.security provider list.
- Add a smoke test that constructs the Kerberos Oid at startup.
When it happens
Trigger: Class-loading of KerberosMultiTier when new Oid("1.2.840.113554.1.2.2") throws GSSException — practically only with a broken/nonstandard JGSS provider or a JVM with a damaged security provider configuration.
Common situations: Unusual JVMs or custom security providers lacking standard GSS mechanism OID support; rarely seen on standard JDKs.
Related errors
- Kerberos authentication failed
- credentials cannot be null
- doExecute returned null
- Error running rest call
- Failed find SHA1PRNG algorithm!
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/e1ca76026826d39b.
Report an issue: GitHub.
Appendix: source
Thrown at kerberos/kerberos-core/src/main/java/org/springframework/security/kerberos/authentication/KerberosMultiTier.java:126
byte[] inToken = new byte[0];
outToken = securityContext.initSecContext(inToken, 0, inToken.length);
established = securityContext.isEstablished();
}
jaasContext.addToken(targetService, outToken);
}
catch (Exception ex) {
throw new BadCredentialsException("Kerberos authentication failed", ex);
}
}
private static Oid createOid(String oid) {
try {
return new Oid(oid);
}
catch (GSSException ex) {
throw new IllegalStateException("Unable to instantiate Oid: ", ex);
}
}
private KerberosMultiTier() {
}
}
View on GitHub (pinned to 96852e8860)