spring-projects/spring-security · error · IllegalStateException

Unable to instantiate Oid:

Error message

Unable to instantiate Oid: 

What it means

KerberosMultiTier.createOid wraps GSSException from `new Oid(oid)` in an IllegalStateException. The static KERBEROS_OID constant initializes at class load; if the hard-coded Kerberos V5 OID string is rejected by the JGSS provider, class initialization fails.

Solutions

  1. Use a standard Oracle/OpenJDK JGSS provider that supports the Kerberos V5 OID.
  2. Check java.security provider ordering does not remove the SunJGSS provider.
  3. Inspect the GSSException cause for provider-specific details.
  4. As a workaround, construct the Oid manually in your own code to test provider support.
Defensive patterns

Strategy: try-catch

Validate before calling

try {
  new Oid("1.2.840.113554.1.2.2");
} catch (GSSException e) {
  throw new IllegalStateException("JGSS provider lacks Kerberos V5 OID support", e);
}

Try / catch

try {
  Class.forName("org.springframework.security.kerberos.authentication.KerberosMultiTier");
} catch (Throwable t) {
  LOG.error("JGSS provider cannot init KerberosMultiTier", t);
}

Prevention

When it happens

Trigger: Class-loading of KerberosMultiTier when new Oid("1.2.840.113554.1.2.2") throws GSSException — practically only with a broken/nonstandard JGSS provider or a JVM with a damaged security provider configuration.

Common situations: Unusual JVMs or custom security providers lacking standard GSS mechanism OID support; rarely seen on standard JDKs.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/e1ca76026826d39b. Report an issue: GitHub.

Appendix: source

Thrown at kerberos/kerberos-core/src/main/java/org/springframework/security/kerberos/authentication/KerberosMultiTier.java:126

				byte[] inToken = new byte[0];
				outToken = securityContext.initSecContext(inToken, 0, inToken.length);

				established = securityContext.isEstablished();
			}

			jaasContext.addToken(targetService, outToken);
		}
		catch (Exception ex) {
			throw new BadCredentialsException("Kerberos authentication failed", ex);
		}
	}

	private static Oid createOid(String oid) {
		try {
			return new Oid(oid);
		}
		catch (GSSException ex) {
			throw new IllegalStateException("Unable to instantiate Oid: ", ex);
		}
	}

	private KerberosMultiTier() {
	}

}

View on GitHub (pinned to 96852e8860)