Download full document:

SSL2 ERRORS

SSL2 ERRORS

Error CodeError Code(Decimal)Error Code(Hex)Error Message
NSERR_SSL_FIPSCARDLOCKED35840xe00FIPS card locked due to three unsuccessful login attempts
NSERR_SSL_DOMINCOMPAT35850xe01Certificate is registered to a different domain; use the no domain check option to force the operation
NSERR_SSL_NOMTHDCHANGE35860xe02Cannot change refresh method of CRL
NSERR_SSL_URLSRVRNEEDED35870xe03Either URL or server-IP required on CRL
NSERR_SSL_INVALID_URL35880xe04Invalid URL
NSERR_SSL_MIXPARAMS35890xe05LDAP and HTTP parameters cannot both be specified
NSERR_SSL_PKEY_MINSIZE35900xe06Certificate of size smaller than 512 bits not supported
NSERR_SSL_SYNCINPROGRESS35910xe07Another synchronization is already in process, please try again later
NSERR_SSL_SYNCFAILED35920xe08Synchronization failed, please try again
NSERR_SSL_CIPHGRP_REFCNT35930xe09Cipher group has bound entities or is referenced by an SSL vserver or SSL service
NSERR_SSL_CVM_NODSA35940xe0ALoading DSA(DSS) certificate and key not supported on this platform
NSERR_CERTHASHHEADER35950xe0BCertHash header tag mandatory if certHash is enabled
NSERR_SSL_CRLINREFRESH35960xe0CCRL refresh in progress, details cannot be displayed
NSERR_SSL_CRLMEM_EXCEEDS35970xe0DCRL memory exhausted. Cannot load any more CRLs
NSERR_SSL_CRLINDELETION35980xe0ECRL deletion in progress, details cannot be displayed
NSERR_SSL_INDELETE_NOREFRESH35990xe0FCRL deletion in progress, cannot be refreshed
NSERR_SSL_INREFRESH_NODELETE36000xe10CRL refresh in progress, cannot be removed
NSERR_NOMIX36010xe11Cannot specify both HTTP data insertion and SSL actions
NSERR_NOPOLICY_NONTRSVC36020xe12Cannot bind SSL policy to SSL backend service
NSERR_SSL_SSLPOL_BIND_CONST36030xe13Cannot bind non-SSL policy to SSL vserver/service
NSERR_SSL_NO_USABLE_CIPHERS36040xe14No usable ciphers configured on the SSL vserver/service
NSERR_SSL_CERT_NOT_CA36050xe15Not a CA certificate
NSERR_SSL_CACERT_NO_CRLSIGN36060xe16Specified certificate is either not a CA cert, or does not have privileges to issue CRLs
NSERR_SSL_CRL_EXPIRED36070xe17CRL has expired
NSERR_SSL_CRL_NOTYET_VALID36080xe18CRL is not yet valid
NSERR_SSL_PARSING_DELTA_CRL_EXTN36090xe19Parsing of Delta-CRL extension failed
NSERR_SSL_DELTA_CRL_MISSING_BASE_CRL36100xe1ABase-CRL for the specified Delta-CRL is missing
NSERR_NOFIPSCIPHER36110xe1BSpecified cipher/cipher-alias is not FIPS-approved
NSERR_NOFIPSCIPHERGRP36120xe1CCipher group does not contain all FIPS-approved ciphers
NSERR_NONFIPSCIPHERTOGRP36130xe1DCannot add non FIPS approved cipher to cipher group
NSERR_NONFIPSALIASTOGRP36140xe1ECannot add non FIPS approved cipher alias to cipher group
NSERR_NONFIPSGROUPTOGRP36150xe1FCannot add non FIPS cipher group to another cipher group
NSERR_SSL_IMPORT_FIPSKEY_NAME_MISMATCH36160xe20Specified FIPS key name does not match with the exported FIPS key name
NSERR_SSL_PKEY_SIZE_CA36170xe21CA certificate of size greater than 4096 bits not supported
NSERR_SSL_CRL_PORT_MISMATCH36180xe22Port specified in URL does not match -port parameter
NSERR_SSL_PKEY_SIZE_VPX36190xe23Certificate with key size greater than RSA512 or DSA512 bits not supported
NSERR_SSL_DH_SIZE_VPX36200xe24DH params of size greater than 512 bits not supported
NSERR_NOENT_CIPHER36210xe25No such cipher/cipherAlias/cipherGroup
NSERR_FIPSFWWRONGMAJOR36220xe26The current firmwares major version is not supported for update operation
NSERR_FIPSFWWRONGMINOR36230xe27The current firmwares minor version is not supported for update operation
NSERR_FIPSFWUPDATED36240xe28The current firmware is already updated to 4.6.1
NSERR_SSL_PENDING_CMDS36250xe29Other commands (card health monitoring/traffic) are pending to FIPS card. Please try the firmware update command after some time
NSERR_FIPSFWUPDATEDOREBOOT36260xe2AOperation not permitted - FIPS card firmware update done, please reboot the system
NSERR_SSL_SNI_NOTENABLE36270xe2BSNI feature not enabled on the vserver/service
NSERR_SSL_NO_CN36280xe2CCommonName not present in certificate, it is must for a certificate to use for SNI
NSERR_SSL_DUP_SNICERT36290xe2DTrying to bind SNI certificate with duplicate CommonName, operation failed
NSERR_SSL_SNI_NOTVALID_SERV36300xe2EOperation not permitted - SNI feature not supported on SSL backend/internal service
NSERR_OCSP_REFERENCES36320xe30OCSP responder is bound to a vserver/certkey pair. Use unbind ssl certkey.
NSERR_OCSP_SIGNER_NOKEY36330xe31Signing certificate must also have a private key.
NSERR_SSL_NOT_SUPPORTED36340xe32OCSP responder must be an HTTP server; SSL is not supported.
NSERR_OCSP_TOO_MANY_RESPONDERS36350xe33Too many OCSP responders configured to add another. Please delete some and try again.
NSERR_OCSP_NO_DNS_SERVER_CONFIGURED36360xe34Unable to resolve DNS name.
NSERR_SSL_DUP_SNICERT_BRKLINK36370xe35Some of the existing SNI cert bindings are broken due to presence of certificate with duplicate Common Name.
NSERR_SSL_NO_CN_BRLLINK36380xe36All exitsing SNI Cert bindings are broken during update operation due to missing Common Name.
NSERR_NGFIPSRESETREBOOT36390xe37Operation not permitted - FIPS card was reset, please reboot the system
NSERR_NGFIPSINITREBOOT36400xe38Operation not permitted - FIPS card was initialized, please reboot the system
NSERR_FIPSCMDTIMEOUT36410xe39Operation timedout on the FIPS card, please try again
NSERR_SSL_SIMTIMEOUT36420xe3aOperation timed out or repeated, please wait for 10 mins and redo the SIM/HA configuration steps.
NSERR_SSL_NGFIPS_QFULL36430xe3bFIPS card command queue full. Please try again later
NSERR_SSL_NOMEM_VSVRSRVLISTNODE36440xe3cFailed to allocate memory for CertkeyVserverServList Node.
NSERR_SSL_CERTKEY_SIZE6436450xe3dCertificate with key size (modulus) that is not multiple of 512 bits is not supported
NSERR_SNI_ATK36460xe3eHost header field in the HTTP request does not match with the SNI domain name
NSERR_SNI_NOHOSTHDR36470xe3fHost header missing in the HTTP header for SNI enabled session
NSERR_CRL_SHMEM_ALLOC_FAIL36480xe40Crl node allocation in the shared mem is failed
NSERR_SSL_PE_NO_SET_UNSET36490xe41Set/Unset operation not supported for classic SSL polices
NSERR_SSL_NOT_CTL_POL36500xe42Not a control policy
NSERR_SSL_NOT_DATA_POL36510xe43Not a data policy
NSERR_SSL_TYPE_REQD36520xe44Type is required
NSERR_SSL_NOT_PI_POL36530xe45Advanced policy attributes specified with classic policy
NSERR_SSL_PE_POL_POL_LBL36540xe46Cannot bind classic policy to policy label
NSERR_SSL_CERT_MISSING_PARAM36550xe47Required parameters missing in the certificate. Please check the certificate for completeness
NSERR_SSL_NOMEM_CERTKEY_OCSPRESP_LISTNODE36560xe48Failed to allocate memory for CertkeyOCSPRespList Node.
NSERR_SSL_OCSP_DUPLICATE36570xe49An ocspResponder is already bound with the specified priority.
NSERR_SSL_BIND_CP36580xe4aBinding of SSL classic policy is not supported, use equivalent advanced SSL policy
NSERR_SSL_ADD_CP36590xe4bAdding SSL classic policy is not supported, use equivalent advanced rule
NSERR_SSL_BUNDLE_IC_FILE_EXISTS36600xe4cCertificate file for intermediate certificate already exists.
NSERR_SSL_BUNDLE_SCERT_MISSING36610xe4dServer certificate must be placed first in certificate bundle file.
NSERR_SSL_BUNDLE_CERT_MISSING36620xe4eNo certificates present in the certificate bundle file.
NSERR_SSL_BUNDLE_FAILED36630xe4fProcessing of certificate bundle file failed.
NSERR_SSL_BUNDLE_PARSE_ERR36640xe50Unable to parse the certificate bundle file.
NSERR_SSL_BUNDLE_MAX_CERT36650xe51Exceeded maximum Intermediate certificates limit of 9.
NSERR_SSL_BUNDLE_MAX_KEY36660xe52Only one private-key is allowed in the certificate bundle file.
NSERR_SSL_BUNDLE_IC_FILE_CREATE_FAILED36670xe53Intermediate certificate file creation failed.
NSERR_SSL_SKIPCA_OPNOTPER36680xe54skipCA is not permitted for this entity.
NSERR_SSL_ISSUER_MISMATCH36690xe55Certificate Issuer mismatch
NSERR_SSL_SET_POLICY_ACTION_TYPE36700xe56Action type cannot be changed from the previous configured action type
NSERR_SSL_DTLS_NOTSUPP36710xe57Virtual server of type DTLS is not supported on this platform
NSERR_SSL_INVALID_CN_NAME36720xe58Invalid Common Name.
NSERR_SSL_ECC_NOT_SUPPORTED36730xe59ECDHE ciphers supported only on FE SSL entities on VPX, MPX and BE MPX
NSERR_SSL_NO_PROTOCOL_ENABLED36740xe5aSSL or TLS protocols not enabled on the service.
NSERR_DTLS_PROFILE_REFEXT36760xe5cDTLS profile is referenced by a vserver or front-end service.
NSERR_SSL_NO_ECC_CURVES36770xe5dNo ECC curves bound for ECDHE ciphers.
NSERR_CRYPTODEV_MAX_LIMIT36780xe5eCrypto Device count exceeds maximum available.
NSERR_SSL_PROFILE_ATTACHED36790xe5fOperation not permitted. Use set ssl profile for setting these parameters.
NSERR_SSL_PROFILE_USED36800xe60Profile is being used by Virtual Server or Service.
NSERR_SSL_PROFILE_NOT_VAILD_PARAM36810xe61Specified parameters are not applicable for this type of SSL profile.
NSERR_IMPORT_SSL_INVALID_DHFILE_ERROR_OBJECT36820xe62Import failed:DH file being imported is invalid.
NSERR_IMPORT_SSL_INVALID_CRLFILE_ERROR_OBJECT36830xe63Import failed:CRL file being imported is invalid.
NSERR_IMPORT_SSL_INVALID_CERTFILE_ERROR_OBJECT36840xe64Import failed:Certificate file being imported is invalid
NSERR_IMPORT_SSL_INVALID_KEYFILE_ERROR_OBJECT36850xe65Import failed:Key file being imported is invalid
NSERR_FIPSFW_FILEPATH36860xe66Invalid firmware file path
NSERR_FIPSFW_FILEOPEN36870xe67Unable to open firmware file
NSERR_FIPSFW_FILEIO36880xe68Read error occurred for firmware file
NSERR_FIPSFW_FSTAT36890xe69Failed to get status of firmware file
NSERR_FIPSFW_AUTH_FILEPATH36900xe6aInvalid firmware signature file path
NSERR_FIPSFW_AUTH_FILEOPEN36910xe6bUnable to open firmware signature file
NSERR_FIPSFW_AUTH_FILEIO36920xe6cRead error occurred for firmware signature file
NSERR_FIPSFW_AUTH_FSTAT36930xe6dFailed to get status of firmware signature file
NSERR_FIPSFW_BEGIN_ERROR36940xe6eFirmware update process failed BEGIN command
NSERR_FIPSFW_UPDATE_ERROR36950xe6fFirmware update process failed UPDATE command
NSERR_FIPSFW_END_ERROR36960xe70Firmware update process failed END command
NSERR_FIPSFW_STATE_ERROR36970xe71Firmware update process failed, invalid state
NSERR_FIPSFW_INVALID_CHUNK_TYPE36980xe72Firmware update process failed, invalid chunk type
NSERR_SSL_OCSP_WITH_CK_HSMKEY36990xe73Configuration of OCSP signing certificate with external HSM key not supported.
NSERR_SSL_HSMKEY_DEFLOCATION37000xe74Input HSM Key Simple file not present under the default directory /var/opt/nfast/kmdata/local/
NSERR_SSL_HSMKEY_IDENT_MISMATCH37010xe75HSM Key Name must be same as HSM Key Ident
NSERR_SSL_HSMKEY_DTLS37020xe76HSM Key bind with DTLS Vserver is not supported.
NSERR_SSL_HSMKEY_BUNDLE37030xe77Addition of certificate-bundle with external HSM Key is not supported.
NSERR_CPE_EXPRESSION_PARTITION_INVALID37040xe78Classic expression is not supported in current partition.
NSERR_AP_INVALID_EXPRESSION37050xe79Expression value not supported.
NSERR_SSL_DH_BUSY37060xe7aDH Param in use. Please try later...
NSERR_FIPSFW22_MINKEYSIZE37070xe7bKey size less than 2048 is not supported on FIPS Firmware Version 2.2.
NSERR_SSL_MAXSAN37080xe7cMaximum number of SANs reached
NSERR_SSL_BADSNICERT37090xe7dBad SNI certificate
NSERR_SSL_AESGCM_SHA2_NOT_SUPPORTED37100xe7eAES-GCM/SHA2 ciphers not supported on VPX and FIPS
NSERR_SSL_NOCIPHERGRP37110xe7fCipher Group does not exist.
NSERR_SSL_SVCVSR_NOT_FOUND37120xe80No SSL vserver/service found with this name.
NSERR_SSL_DEF_DTLS_PROFILE37130xe81Cannot modify default DTLS profile.
NSERR_SSL_NOSSLV2REDIRECTOPT_ON_FIPS37140xe82Sslv2 Redirect option is not permitted on MPX-FIPS platform.
NSERR_SSL_OP_ON_NONFIPS_NOT_PERM37150xe83Operation permitted only on MPX-FIPS platform.
NSERR_SSL_LOAD_KEYS37160xe84Loading of internal keys failed.
NSERR_SSL_PASSWORD_DECODE37170xe85Decode of the encrypted passphrase failed.
NSERR_SSL_NOCERT_FILE37180xe86Certificate file name not specified.
NSERR_SSL_DEFAULT_CERT_DEL37190xe87Cannot delete internal default certificate.
NSERR_SSL_FIPS_CERT37200xe88FIPS certificate cannot be bound as a CA certificate, install the certificate without the FIPS key.
NSERR_SSL_CERTKEY_HSM37210xe89Cannot bind a certificate with HSM key to a service.
NSERR_SSL_DEFAULT_CERT_BIND37220xe8aCannot bind internal default certificate.
NSERR_SSL_CMD_DEPRECATED37230xe8bCommand deprecated, operation not applicable to this platform.
NSERR_SSL_NO_LIC37240xe8cOnly export ciphers are allowed without proper SSL license.
NSERR_SSL_DTLS_NA37250xe8dCommand arguments does not apply to vserver/service of type DTLS.
NSERR_SSL_ECC_SUPPORT37260xe8eECC curve is not supported for this entity/platform.
NSERR_SSL_PROFILE_FE37270xe8fCannot bind front-end profile to a back-end SSL service.
NSERR_SSL_PROFILE_BE37280xe90Cannot bind back-end profile to a front-end SSL vserver.
NSERR_SSL_OP_ON_FIPS_WOFW22_NOT_PERM37290xe91Operation not permitted on MPX-FIPS platform without FIPS firmware version 2.2 or higher.
NSERR_SSL_NONSSL_VSERVER37300xe92Vserver is not of type SSL.
NSERR_SSL_UDP_DTLS37310xe93Cannot bind policy to vserver of type DTLS.
NSERR_SSL_TLS11_12_SUPPORT37320xe94Enabling of TLSv1.1/1.2 is not supported on this entity/platform.
NSERR_SSL_HSM_KEY_SVC_SVCGRP37330xe95Binding of certificate with HSM key is not supported on back-end service or serviceGroup.
NSERR_DTLS_PROFILE37340xe96Cannot bind DTLS profile to a SSL vserver.
NSERR_SSL_PROFILE_NO_USABLE_CIPHERS37350xe97No usable ciphers configured for some of the SSL vserver/service binded to this profile
NSERR_SSL_CIPHGRP_NO_USABLE_CIPHERS37360xe98No usable ciphers configured for some of the SSL vserver/service binded to this cipher group
NSERR_SSL_PROFILE_UNSET_DEFAULT37370xe99Unsetting a default SSL Profile is not allowed
NSERR_SSL_DEFAULT_PROFILE_ENABLED37380xe9aDisabling ssl default profile is not allowed
NSERR_SSL_PROFILE_DEFAULT_DISABLED37390xe9bOperation not permitted. To do this Enable default ssl profile by setting set ssl parameter -defaultProfile E
NSERR_SSL_PROFILE_DEFAULT_ENABLED37400xe9cOperation not permitted. To do this Disable default ssl profile by setting set ssl parameter -defaultProfile D
NSERR_SSL_CIPHER_EXIST_HIGHER_PRI37410xe9dSpecified cipher is already bound with higher priority
NSERR_SSL_DEFAULT_PROFILE_PERM37420xe9eDefault ssl profile can not be removed
NSERR_SSL_DH_SIZE_16B37430xe9fDH params of size is not 16B aligned
NSERR_SSL_NOCIPHERREDIRECTOPT37440xea0The cipher redirect option is not supported for SSL Service
NSERR_SSL_NOCLIENTAUTHOPT37450xea1The client auth option is not supported for SSL Service
NSERR_SSL_NOSSLV2REDIRECTOPT37460xea2The SSLv2 redirect option is not supported for SSL Service
NSERR_SSL_NONONFIPSCIPHERSOPT37470xea3The nonFipsCiphers option is not applicable any more
NSERR_SSL_NOCIPHERREDIRECTOPT_ON_FIPS37480xea4Cipher Redirect option is not permitted on MPX-FIPS platform.
NSERR_SSL_NOSSL2PROTOOPT_ON_FIPS37490xea5Ssl2 protocol option is not permitted on MPX-FIPS platform.
NSERR_SSL_CANNOT_BIND_VSERVER37500xea6Front end service cannot be bound to a vserver.
NSERR_SSL_SERVERAUTHNOTSUPP37510xea7ServerAuth Operation is not supported for front end service.
NSERR_SSL_SERVERAUTH_SNI_REQUIRED37520xea8Argument pre-requisite missing serverAuth == ENABLED or SNIEnable == ENABLED
NSERR_SSL_CN_REQUIRED37530xea9Argument pre-requisite missing commonName
NSERR_SSL_DTLSPROFNOTSUPP37540xeaaCannot set DTLS Profile Name for a ssl service.
NSERR_SSL_PUSHENCNOTSUPP37550xeabPush encryption trigger is not supported for SSL Service.