Error description when the operation status is Failed. For example:
{ "error": { "code": "cagw-4016", "message": "Could not find certificate", "details": [] }}See below for the supported codes.
Code | Description | Audit |
|---|---|---|
cagw-4000 | The specified resource was not found. |
|
cagw-4001 | Could not parse CSR. |
|
cagw-4002 | Could not build a valid subject name. |
|
cagw-4003 | Could not find cert type configured for profile. |
|
cagw-4004 | Could not find cert definition configured for profile. |
|
cagw-4005 | Could not find user type configured for profile. |
|
cagw-4006 | Invalid subject DN name. |
|
cagw-4007 | Invalid CSR. |
|
cagw-4008 | Invalid format requested. |
|
cagw-4009 | Invalid protection. |
|
cagw-4010 | Invalid private key. |
|
cagw-4011 | Invalid JSON body. |
|
cagw-4012 | Invalid HTTP request message. |
|
cagw-4013 | Invalid HTTP request method. |
|
cagw-4014 | Invalid profile identifier. |
|
cagw-4015 | Distinguished Name not found. |
|
cagw-4016 | Could not find a certificate with the specified serial number. |
|
cagw-4017 | Could not find certificate with DN. |
|
cagw-4018 | CA with specified name not found. |
|
cagw-4019 | The certificate owner's account is deactivated. |
|
cagw-4020 | Unable to manage certificate. |
|
cagw-4021 | No profiles are configured for this CA. |
|
cagw-4022 | A PasswordProtection object must be supplied if the requested type is PKCS12. |
|
cagw-4023 | An invalid action type was received. |
|
cagw-4024 | Could not get the CA capabilities. |
|
cagw-4025 | Could not get the capability. |
|
cagw-4026 | Invalid certificate validity period. |
|
cagw-4027 | Access Denied. |
|
cagw-4028 | An enrollment request must have either a |
|
cagw-4029 | Both |
|
cagw-4030 | Unable to manage user. |
|
cagw-4031 |
|
|
cagw-4032 | Repeated subject variable given to the template subject builder. Variable names cannot be repeated when using the template subject builder. |
|
cagw-4033 | Subject variable missing. |
|
cagw-4034 | Missing profile identifier. |
|
cagw-4035 | Invalid or missing revocation reason. |
|
cagw-4036 | Invalid expression for |
|
cagw-4037 | Request body is empty. |
|
cagw-4038 | Invalid private key usage percentage. |
|
cagw-4039 | Missing value property of subject variable pair. |
|
cagw-4040 | Invalid Subject Alternative Name type supplied. |
|
cagw-4041 | Missing |
|
cagw-4042 | Invalid request parameters. |
|
cagw-4043 | Error in the configuration of one or more managed CAs. |
|
cagw-4044 | Missing enrollment tracking in request properties. |
|
cagw-4045 | Invalid CA capability. |
|
cagw-4046 | No permission to send HTTP headers. |
|
cagw-4047 | Bad connector filter configuration. |
|
cagw-4048 | Issuance denied. |
|
cagw-4049 | Certificate Transparency error. |
|
cagw-4050 | A CmpProtection object must be supplied if the requested type is CMPv2. |
|
cagw-4051 | Too many requests. (Rate-limit — Warning / High if sustained.) |
|
cagw-4052 | Invalid request parameter |
|
cagw-4053 | A CmpProtection object is not supported for this API; please use the appropriate API. |
|
cagw-4054 | Failed to retrieve properties from CA. |
|
cagw-4055 | Required Subject Alternative Name(s) not included. |
|
cagw-4056 | Certificate issuance submitted, but certificate not ready. |
|
cagw-4057 | The certificate was issued, but we could not complete certificate processing. |
|
cagw-4058 | An unexpected error was returned from the CA. |
|
cagw-4500 | Unable to create directory entry. |
|
cagw-4501 | Unsupported operation. |
|
cagw-4502 | No certificate serial numbers were supplied for the certificate management operation. |
|
cagw-4503 | No certificate management action supplied. |
|
cagw-4504 | Invalid request, missing parameters. |
|
cagw-4505 | No PKCS#12 passcode supplied. |
|
cagw-4506 | Failed to validate proof of possession of private key. |
|
cagw-4507 | No public key found in request. |
|
cagw-4508 | Failed to parse PKCS#10 Certificate Request (CSR). |
|
cagw-4509 | CSR required to prove possession of the private key. |
|
cagw-4510 | Only one certificate request is permitted per message. |
|
cagw-4511 | Unable to parse external Subject Alternative Name General Names structure. |
|
cagw-4512 | Unable to parse external X.509 extensions structure. |
|
cagw-4513 | The certificate owner's account is in a state that does not permit any operations. |
|
cagw-4514 | A change-DN operation has been requested; however, the previous Subject DN supplied does not exist. |
|
cagw-4515 | Invalid request format. |
|
cagw-4516 | Warning: The certificate is already in the requested state. |
|
cagw-4517 | Warning: The certificate serial number does not reference any of the certificates belonging to this subject. |
|
cagw-4518 | Invalid Subject DN. The requested Subject DN is not compatible with the issuing CA. |
|
cagw-4519 | No response format supplied. |
|
cagw-4520 | Invalid public key in request. |
|
cagw-4521 | Warning: The user is already in the requested state. |
|
cagw-4522 | Unable to recover the requested keys/certificates. |
|
cagw-4523 | The requested certificate definition does not match the certificate's original definition. |
|
cagw-4524 | Unable to build PKCS#12. |
|
cagw-4525 | The request includes a public key, but the policy is configured for server-side key generation. |
|
cagw-4526 | Invalid response format supplied. |
|
cagw-4527 | The user has no certificates to unsuspend. |
|
cagw-4528 | Failed to parse X.509 Certificate. |
|
cagw-4529 | Private key provided but policy is not configured for key backup. |
|
cagw-4530 | For X509 enrollment, the request must include either a CSR or a public/private key pair. |
|
cagw-4531 | If you provide a public key, you must also provide the private key. |
|
cagw-4532 | For PKCS12 enrollment: request must have |
|
cagw-4533 | Either |
|
cagw-4534 | Certificate template requires key archival, but no private key was provided. |
|
cagw-4535 | No public key was supplied either inside a CSR or externally. |
|
cagw-4536 | 'Publish certificate in Active Directory' is enabled, but the user does not exist in AD. |
|
cagw-4537 | No certificates found for the subject DN. |
|
cagw-4538 | No user exists in SM Cloud CA for this Client. |
|
cagw-4539 | Invalid Client Certificate. Subject must contain a |
|
cagw-4540 | PKIaaS CA connector configured to use an HTTP header, but header missing/invalid. |
|
cagw-4541 | Invalid Client Certificate. The client does not have the required role permission. |
|
cagw-4542 | Received invalid or null |
|
cagw-4543 | Invalid Client. The IdP for this client was not found. |
|
cagw-4544 | Product license violation. |
|
cagw-4545 | Product license expired or not yet valid. |
|
cagw-4560 | CMP has not been configured. |
|
cagw-4561 | CMP protection not correctly defined. |
|
cagw-4562 | CMP header template not correctly defined. |
|
cagw-5000 | An unexpected error occurred! (generic 500) |
|
cagw-5001 | Unexpected error encoding certificate! |
|
cagw-5002 | No PKCS#12 returned with recovery request. |
|
cagw-5500 | Unable to create connection to CA. |
|
cagw-5501 | Unable to create user account in CA. |
|
cagw-5502 | Error processing certificate issuance request. |
|
cagw-5503 | Error obtaining a credential to connect to the CA. |
|
cagw-5504 | Error processing certificate information request. |
|
cagw-5505 | Unable to create connection to LDAP. |
|
cagw-5506 | An LDAP error occurred. |
|
cagw-5507 | Error processing certificate management request. |
|
cagw-5508 | Certificate Profile configuration error. |
|
cagw-5509 | Empty response from internal API. |
|
cagw-5510 | Could not parse internal API response. |
|
cagw-5511 | Could not instantiate subject builder class. |
|
cagw-5512 | Template subject builder could not construct a subject. |
|
cagw-5513 | Error creating Java Admin Toolkit object. |
|
cagw-5514 | Error populating certificate cache. |
|
cagw-5515 | Error searching certificate cache. |
|
cagw-5516 | Invalid directory mode setting. Valid modes: |
|
cagw-5517 | Invalid subject variable supplied. |
|
cagw-5518 | Can't find the template in the CA (Microsoft CA). |
|
cagw-5519 | Microsoft certificate request signing is not possible; the configured signing algorithms are not supported with the key. |
|
cagw-5526 | Unable to connect to CA Proxy. |
|
cagw-5527 | Offset can't be less than 1. |
|
cagw-5528 | Limit can't be less than 1. |
|
cagw-5529 | Unable to perform requested operation. |
|
cagw-5530 | If 'publish certificate in AD' is enabled, then the enrollment agent PKCS12 store and password must be provided in the profile configuration. |
|
cagw-5531 | Enrollment agent PKCS12 store and password are required in the profile. |
|
cagw-5533 | At least one Key Recovery Agent configuration is required when recovering keys from a Microsoft CA. |
|
cagw-5535 | Could not parse |
|
cagw-5536 | [PKIaaS] Certificate Decoding Failed. |
|
cagw-5537 | [PKIaaS] Failed to perform |
|
cagw-5538 | [PKIaaS] Failed to perform |
|
cagw-5539 | [PKIaaS] Failed to perform |
|
cagw-5540 | [PKIaaS] Failed to perform |
|
cagw-5541 | [PKIaaS] Failed to perform |
|
cagw-5542 | [PKIaaS] Failed to perform |
|
cagw-5543 | [PKIaaS] IAIK Certificate Factory not found. |
|
cagw-5544 | Unexpected error encoding certificate request! |
|
cagw-5545 | [PKIaaS] Failed to generate the JWT token. |
|
cagw-5546 | [PKIaaS] Unable to fetch/parse the SM Cloud CAID and partitionID. |
|
cagw-5547 | [PKIaaS] Failed to perform |
|
cagw-5548 | [PKIaaS] Failed to perform |
|
cagw-5549 | [PKIaaS] Retrieved |
|
cagw-5550 | Usage API indicates block. |
|
cagw-5551 | Usage API error. |
|
cagw-5552 | [PKIaaS] Failed to create |
|