Error description when the operation status is Failed. For example:

{
"error": {
"code": "cagw-4016",
"message": "Could not find certificate",
"details": []
}
}

See below for the supported codes.

Code

Description

Audit

cagw-4000

The specified resource was not found.

(error) 

cagw-4001

Could not parse CSR.

(error) 

cagw-4002

Could not build a valid subject name.

(error) 

cagw-4003

Could not find cert type configured for profile.

(error) 

cagw-4004

Could not find cert definition configured for profile.

(error) 

cagw-4005

Could not find user type configured for profile.

(error) 

cagw-4006

Invalid subject DN name.

(error) 

cagw-4007

Invalid CSR.

(error) 

cagw-4008

Invalid format requested.

(error) 

cagw-4009

Invalid protection.

(error) 

cagw-4010

Invalid private key.

(error) 

cagw-4011

Invalid JSON body.

(error) 

cagw-4012

Invalid HTTP request message.

(error) 

cagw-4013

Invalid HTTP request method.

(error) 

cagw-4014

Invalid profile identifier.

(error) 

cagw-4015

Distinguished Name not found.

(error) 

cagw-4016

Could not find a certificate with the specified serial number.

(error) 

cagw-4017

Could not find certificate with DN.

(error) 

cagw-4018

CA with specified name not found.

(error) 

cagw-4019

The certificate owner's account is deactivated.

(error) 

cagw-4020

Unable to manage certificate.

(error) 

cagw-4021

No profiles are configured for this CA.

(error) 

cagw-4022

A PasswordProtection object must be supplied if the requested type is PKCS12.

(error) 

cagw-4023

An invalid action type was received.

(error) 

cagw-4024

Could not get the CA capabilities.

(error) 

cagw-4025

Could not get the capability.

(error) 

cagw-4026

Invalid certificate validity period.

(error) 

cagw-4027

Access Denied.

(tick) 

cagw-4028

An enrollment request must have either a subjectVariables or subjectDn entry.

(error) 

cagw-4029

Both subjectVariables and subjectDn are present. Only one may be present in an enrollment request.

(error) 

cagw-4030

Unable to manage user.

(error) 

cagw-4031

includeCa Applies only to the required PKCS12 format.

(error) 

cagw-4032

Repeated subject variable given to the template subject builder. Variable names cannot be repeated when using the template subject builder.

(error) 

cagw-4033

Subject variable missing.

(error) 

cagw-4034

Missing profile identifier.

(error) 

cagw-4035

Invalid or missing revocation reason.

(tick) 

cagw-4036

Invalid expression for $filter parameter.

(error) 

cagw-4037

Request body is empty.

(error) 

cagw-4038

Invalid private key usage percentage.

(error) 

cagw-4039

Missing value property of subject variable pair.

(error) 

cagw-4040

Invalid Subject Alternative Name type supplied.

(error) 

cagw-4041

Missing requiredFormat object in enrollment.

(error) 

cagw-4042

Invalid request parameters.

(error) 

cagw-4043

Error in the configuration of one or more managed CAs.

(error) 

cagw-4044

Missing enrollment tracking in request properties.

(error) 

cagw-4045

Invalid CA capability.

(error) 

cagw-4046

No permission to send HTTP headers.

(tick) 

cagw-4047

Bad connector filter configuration.

(error) 

cagw-4048

Issuance denied.

(tick) 

cagw-4049

Certificate Transparency error.

(tick) 

cagw-4050

A CmpProtection object must be supplied if the requested type is CMPv2.

(error) 

cagw-4051

Too many requests. (Rate-limit — Warning / High if sustained.)

(tick) 

cagw-4052

Invalid request parameter preferredPageSize. Must not exceed configured MaxCertificateEventsPageSize.

(error) 

cagw-4053

A CmpProtection object is not supported for this API; please use the appropriate API.

(error) 

cagw-4054

Failed to retrieve properties from CA.

(error) 

cagw-4055

Required Subject Alternative Name(s) not included.

(tick) 

cagw-4056

Certificate issuance submitted, but certificate not ready.

(error) 

cagw-4057

The certificate was issued, but we could not complete certificate processing.

(error) 

cagw-4058

An unexpected error was returned from the CA.

(error) 

cagw-4500

Unable to create directory entry.

(error) 

cagw-4501

Unsupported operation.

(error) 

cagw-4502

No certificate serial numbers were supplied for the certificate management operation.

(error) 

cagw-4503

No certificate management action supplied.

(error) 

cagw-4504

Invalid request, missing parameters.

(error) 

cagw-4505

No PKCS#12 passcode supplied.

(error) 

cagw-4506

Failed to validate proof of possession of private key.

(tick) 

cagw-4507

No public key found in request.

(error) 

cagw-4508

Failed to parse PKCS#10 Certificate Request (CSR).

(error) 

cagw-4509

CSR required to prove possession of the private key.

(error) 

cagw-4510

Only one certificate request is permitted per message.

(error) 

cagw-4511

Unable to parse external Subject Alternative Name General Names structure.

(error) 

cagw-4512

Unable to parse external X.509 extensions structure.

(error) 

cagw-4513

The certificate owner's account is in a state that does not permit any operations.

(tick) 

cagw-4514

A change-DN operation has been requested; however, the previous Subject DN supplied does not exist.

(error) 

cagw-4515

Invalid request format.

(error) 

cagw-4516

Warning: The certificate is already in the requested state.

(tick) 

cagw-4517

Warning: The certificate serial number does not reference any of the certificates belonging to this subject.

(tick) 

cagw-4518

Invalid Subject DN. The requested Subject DN is not compatible with the issuing CA.

(tick) 

cagw-4519

No response format supplied.

(error) 

cagw-4520

Invalid public key in request.

(error) 

cagw-4521

Warning: The user is already in the requested state.

(tick) 

cagw-4522

Unable to recover the requested keys/certificates.

(tick) 

cagw-4523

The requested certificate definition does not match the certificate's original definition.

(tick) 

cagw-4524

Unable to build PKCS#12.

(error) 

cagw-4525

The request includes a public key, but the policy is configured for server-side key generation.

(tick) 

cagw-4526

Invalid response format supplied.

(error) 

cagw-4527

The user has no certificates to unsuspend.

(error) 

cagw-4528

Failed to parse X.509 Certificate.

(error) 

cagw-4529

Private key provided but policy is not configured for key backup.

(tick) 

cagw-4530

For X509 enrollment, the request must include either a CSR or a public/private key pair.

(error) 

cagw-4531

If you provide a public key, you must also provide the private key.

(error) 

cagw-4532

For PKCS12 enrollment: request must have subjectVariables or subjectDn.

(error) 

cagw-4533

Either subjectVariables, subjectDn or CSR is required for X509 format.

(error) 

cagw-4534

Certificate template requires key archival, but no private key was provided.

(tick) 

cagw-4535

No public key was supplied either inside a CSR or externally.

(error) 

cagw-4536

'Publish certificate in Active Directory' is enabled, but the user does not exist in AD.

(tick) 

cagw-4537

No certificates found for the subject DN.

(error) 

cagw-4538

No user exists in SM Cloud CA for this Client.

(error) 

cagw-4539

Invalid Client Certificate. Subject must contain a SERIALNUMBER RDN (SM Cloud CA).

(tick) 

cagw-4540

PKIaaS CA connector configured to use an HTTP header, but header missing/invalid.

(tick) 

cagw-4541

Invalid Client Certificate. The client does not have the required role permission.

(tick) 

cagw-4542

Received invalid or null RequestAttributes object. 

(tick) 

cagw-4543

Invalid Client. The IdP for this client was not found. 

(tick) 

cagw-4544

Product license violation.

(tick) 

cagw-4545

Product license expired or not yet valid.

(tick) 

cagw-4560

CMP has not been configured.

(error) 

cagw-4561

CMP protection not correctly defined.

(error) 

cagw-4562

CMP header template not correctly defined.

(error) 

cagw-5000

An unexpected error occurred! (generic 500)

(error) 

cagw-5001

Unexpected error encoding certificate!

(error) 

cagw-5002

No PKCS#12 returned with recovery request.

(error) 

cagw-5500

Unable to create connection to CA.

(tick) 

cagw-5501

Unable to create user account in CA.

(error) 

cagw-5502

Error processing certificate issuance request.

(error) 

cagw-5503

Error obtaining a credential to connect to the CA.

(tick) 

cagw-5504

Error processing certificate information request.

(error) 

cagw-5505

Unable to create connection to LDAP.

(tick) 

cagw-5506

An LDAP error occurred.

(error) 

cagw-5507

Error processing certificate management request.

(error) 

cagw-5508

Certificate Profile configuration error.

(error) 

cagw-5509

Empty response from internal API.

(error) 

cagw-5510

Could not parse internal API response.

(error) 

cagw-5511

Could not instantiate subject builder class.

(error) 

cagw-5512

Template subject builder could not construct a subject.

(error) 

cagw-5513

Error creating Java Admin Toolkit object.

(error) 

cagw-5514

Error populating certificate cache.

(error) 

cagw-5515

Error searching certificate cache.

(error) 

cagw-5516

Invalid directory mode setting. Valid modes: DO_OP_FAIL_IF_NOT_NEEDED, DO_OP_SUCCEED_IF_NOT_NEEDED, NO_OP, NO_OP_FAIL_IF_NEEDED.

(error) 

cagw-5517

Invalid subject variable supplied.

(error) 

cagw-5518

Can't find the template in the CA (Microsoft CA).

(error) 

cagw-5519

Microsoft certificate request signing is not possible; the configured signing algorithms are not supported with the key.

(error) 

cagw-5526

Unable to connect to CA Proxy.

(tick) 

cagw-5527

Offset can't be less than 1.

(error) 

cagw-5528

Limit can't be less than 1.

(error) 

cagw-5529

Unable to perform requested operation.

(error) 

cagw-5530

If 'publish certificate in AD' is enabled, then the enrollment agent PKCS12 store and password must be provided in the profile configuration.

(error) 

cagw-5531

Enrollment agent PKCS12 store and password are required in the profile.

(error) 

cagw-5533

At least one Key Recovery Agent configuration is required when recovering keys from a Microsoft CA.

(error) 

cagw-5535

Could not parse nextPageIndex.

(error) 

cagw-5536

[PKIaaS] Certificate Decoding Failed.

(error) 

cagw-5537

[PKIaaS] Failed to perform CasApi#getCA.

(error) 

cagw-5538

[PKIaaS] Failed to perform CertificatesApi#listCertificates.

(error) 

cagw-5539

[PKIaaS] Failed to perform CertificatesApi#getCertificate.

(error) 

cagw-5540

[PKIaaS] Failed to perform CertificatesApi#revokeCertificate.

(error) 

cagw-5541

[PKIaaS] Failed to perform EventsApi#listEvents.

(error) 

cagw-5542

[PKIaaS] Failed to perform CertificatesApi#createCertificate.

(error) 

cagw-5543

[PKIaaS] IAIK Certificate Factory not found.

(error) 

cagw-5544

Unexpected error encoding certificate request!

(error) 

cagw-5545

[PKIaaS] Failed to generate the JWT token.

(tick) 

cagw-5546

[PKIaaS] Unable to fetch/parse the SM Cloud CAID and partitionID.

(error) 

cagw-5547

[PKIaaS] Failed to perform OnboardApi#getUser.

(error) 

cagw-5548

[PKIaaS] Failed to perform CasApi#listCAs.

(error) 

cagw-5549

[PKIaaS] Retrieved userid for the client is not in the expected <userid>_<org> format 

(error) 

cagw-5550

Usage API indicates block.

(tick) 

cagw-5551

Usage API error.

(tick) 

cagw-5552

[PKIaaS] Failed to create LdapName object from client DN.

(error)