Skip to content

Error Codes ​

Every expected failure in micro509 carries a machine-readable code. Result-returning APIs put it on result.error.code (or result.code on flattened failures); builder APIs that take developer-supplied config throw a coded error that isResultError detects and error.code discriminates.

This page lists every public error-code union and its members, grouped by the entrypoint that owns it. A repo test extracts these unions from the type declarations and fails when this page and the exported types disagree, in either direction.

Stability

Unions may gain members in minor releases; treat them as non-exhaustive and keep a default branch. Renaming or removing a code only happens in a major release.

micro509/x509 ​

ParseCertificateErrorCode ​

CodeMeaning
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedInput is not a valid DER or PEM X.509 certificate
unsupportedA TeletexString name value holds an octet outside the X.690 §8.23.5.2 initial state, which micro509 does not decode

ParseCertificateSigningRequestErrorCode ​

CodeMeaning
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedInput is not a valid DER or PEM PKCS#10 request
unsupportedA TeletexString name value holds an octet outside the X.690 §8.23.5.2 initial state, which micro509 does not decode

MatchCertificatePrivateKeyErrorCode ​

CodeMeaning
key_mismatchRight algorithm, different key
key_type_mismatchPrivate key algorithm differs from the SPKI's
limit_exceededCertificate exceeds a micro509 decoding limit, see ParseCertificateErrorCode
malformed_certificateCertificate source failed to parse
unsupportedCertificate holds a value micro509 does not decode, see ParseCertificateErrorCode
unsupported_private_keyKey type has no supported SPKI derivation

CreateCertificateErrorCode ​

CodeMeaning
issuer_distinguished_name_emptyRFC 5280 §4.1.2.4 requires a non-empty issuer DN
serial_number_not_positiveSerial must be a positive integer (RFC 5280 §4.1.2.2)
serial_number_too_longSerial DER INTEGER exceeds 20 octets (RFC 5280 §4.1.2.2)
validity_date_invalidnotBefore, notAfter or days gives an invalid date
validity_not_after_before_not_beforeValidity window ends before it starts

NameEncoderErrorCode ​

CodeMeaning
invalid_country_codeCountry attribute is not exactly two letters
name_attribute_emptyAttribute value is empty (RFC 5280 A.1 SIZE (1..))
name_attribute_lone_surrogateAttribute value holds a lone UTF-16 surrogate, which has no UTF-8 encoding
name_attribute_too_longAttribute value exceeds its RFC 5280 A.1 upper bound
relative_distinguished_name_emptyRDN carries no attributes
unsupported_name_fieldAttribute key is not an encodable name field

ExtensionEncoderErrorCode ​

CodeMeaning
authority_info_access_emptyAIA input has no access descriptions
authority_info_access_ocsp_not_uriAn OCSP access method requires a URI location
certificate_policies_emptycertificatePolicies lists no policies
crl_distribution_points_emptycRLDistributionPoints lists no points
directory_name_not_sequencedirectoryName payload is not a DER SEQUENCE
display_text_control_characterexplicitText contains a C0 or C1 control character (RFC 6818 §3)
display_text_ia5_stringexplicitText requested as IA5String (RFC 6818 §3)
display_text_lone_surrogateexplicitText or noticeRef organization holds a lone UTF-16 surrogate
display_text_not_nfcUTF8String or BMPString explicitText is not NFC (RFC 6818 §3)
display_text_out_of_rangeUser-notice DisplayText length outside RFC 5280 bounds
distribution_point_crl_issuer_emptycRLIssuer present but holds no name
distribution_point_crl_issuer_not_directory_namecRLIssuer entries must be directoryNames (RFC 5280 §4.2.1.13)
distribution_point_emptyDistribution point carries no field at all
distribution_point_full_name_emptyfullName present but holds no GeneralName
distribution_point_relative_name_multiple_crl_issuersnameRelativeToCRLIssuer permits at most one cRLIssuer
domain_trailing_dotA dNSName or rfc822Name domain ends in the root dot, outside the RFC 1034 §3.5 preferred name syntax (RFC 5280 §4.2.1.6)
duplicate_extension_oidSame extension OID supplied twice
duplicate_policy_oidSame policy OID listed twice
edwards_key_usage_forbids_agreement_bitEd25519/Ed448 keyUsage asserts an agreement or cipher bit
edwards_key_usage_forbids_key_cert_signEnd-entity Edwards certificate asserts keyCertSign/cRLSign
edwards_key_usage_requires_key_cert_signEdwards CA keyUsage missing keyCertSign
edwards_key_usage_requires_signing_bitEdwards keyUsage missing a signing bit (RFC 9295 §3)
email_name_constraint_names_mailboxrfc822Name constraint names a mailbox (RFC 9549 §2.2)
empty_general_name_valuedNSName/rfc822Name/URI/SRV value is empty
empty_subject_requires_subject_alt_nameEmpty subject DN without a critical, non-empty SAN
extended_key_usage_emptyEKU list is empty
extension_must_be_criticalRFC 5280 fixes this extension as critical
extension_must_be_non_criticalRFC 5280 fixes this extension as non-critical
extension_not_supported_in_contextExtension not allowed in this certificate/CSR context
invalid_bmp_stringBMPString explicitText outside the X.680 BMPString repertoire
invalid_general_name_contentx400Address or ediPartyName contents fail their schema or encoding
invalid_general_name_tagGeneralName tag outside the nine RFC 5280 §4.2.1.6 alternatives
invalid_ia5_stringNon-ASCII input for an IA5String value
invalid_idnDomain name is not valid IDNA2008 (RFC 5891 §4)
invalid_ip_name_constraintIP constraint bytes are not address+mask of one family
invalid_other_name_valueotherName value is not one DER element micro509 can validate
invalid_oidString is not an OID within X.660 arc bounds
invalid_smtp_utf8_mailboxSmtpUTF8Mailbox malformed or domain not A-labels (RFC 9598 §3)
invalid_srv_nameSRVName not _Service.Name with RFC 6335 service and LDH Name
invalid_srv_name_constraintSRVName constraint not _Service.Name, _Service or Name (RFC 4985)
invalid_uri_name_constraintURI constraint not an FQDN or a leading-period domain (RFC 5280 §4.2.1.10)
invalid_visible_stringVisibleString explicitText outside printable ASCII
key_usage_emptykeyUsage asserts no bits
limit_exceededAn OID arc encodes in more than 64 octets, or GeneralName contents nest deeper than 64 levels, a micro509 limit
malformed_known_extension_valuecustomExtensions payload with a known OID fails to decode as it
montgomery_key_usage_forbids_both_cipher_bitsX25519/X448 asserts both encipherOnly and decipherOnly
montgomery_key_usage_forbids_signature_bitX25519/X448 asserts a signature bit (RFC 8410 §12)
montgomery_key_usage_requires_key_agreementX25519/X448 keyUsage missing keyAgreement (RFC 9295 §3)
name_constraints_emptynameConstraints has neither permitted nor excluded subtrees
no_rev_avail_conflictnoRevAvail with cA or a revocation pointer (RFC 9608 §3)
other_name_type_id_has_variantotherName type-id belongs to the srv or smtpUtf8Mailbox variant
path_length_requires_capathLength on a non-CA basicConstraints
path_length_requires_key_cert_signpathLength requires keyUsage asserting keyCertSign
policy_constraints_emptypolicyConstraints carries neither field
policy_mappings_any_policyanyPolicy may not appear in a policy mapping
policy_mappings_emptyMappings list is empty
reserved_policy_qualifier_oidCustom qualifier uses a reserved qualifier OID
smtp_utf8_mailbox_ascii_local_partASCII Local-part must use rfc822Name (RFC 9598 §3)

micro509/verify ​

VerifyErrorCode ​

Meanings are tabled in the verification guide; both tables are enforced against VERIFY_ERROR_CODES by tests.

authority_key_identifier_mismatch, ca_required, certificate_expired, certificate_revoked, common_name_fallback_suppressed, display_text_oversized, ec_domain_parameters_missing, explicit_policy_required, extended_key_usage_invalid, initial_policy_set_not_satisfied, intermediate_eku_constraint, issuer_not_found, key_cert_sign_required, name_constraints_violated, no_rev_avail_conflict, no_trusted_root, path_length_exceeded, path_building_limit_exceeded, revocation_indeterminate, self_signed_leaf_not_allowed, signature_invalid, subject_alt_name_mismatch, unrecognized_critical_extension, unsupported_initial_name_constraints, unsupported_name_constraints, unsupported_signature_algorithm_parameters, unsupported, limit_exceeded

MatchServiceIdentityErrorCode ​

CodeMeaning
common_name_fallback_suppressedCN match suppressed by presented identifiers
limit_exceededThe certificate exceeds a micro509 decoding limit, see ParseCertificateErrorCode
service_identity_mismatchSRV-ID or URI-ID service part does not match
subject_alt_name_mismatchNo SAN matches the requested identity
unsupportedThe certificate holds a value micro509 does not decode, see ParseCertificateErrorCode
unsupported_service_identity_typeIdentity type has no matcher

micro509/revocation ​

ParseCertificateRevocationListErrorCode ​

CodeMeaning
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedInput is not a valid DER or PEM CRL
unsupportedA TeletexString name value holds an octet outside the X.690 §8.23.5.2 initial state, which micro509 does not decode

ParseOcspRequestErrorCode ​

CodeMeaning
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedInput is not a valid DER or PEM OCSP request
unsupportedA TeletexString name value holds an octet outside the X.690 §8.23.5.2 initial state, which micro509 does not decode

ParseOcspResponseErrorCode ​

CodeMeaning
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedInput is not a valid DER or PEM OCSP response
unsupportedA TeletexString name value holds an octet outside the X.690 §8.23.5.2 initial state, which micro509 does not decode

CheckCertificateRevocationAgainstCrlErrorCode ​

CodeMeaning
crl_sign_not_permittedCRL signer's keyUsage lacks cRLSign, or a v3 signer has no keyUsage
issuer_mismatchCRL issuer does not match the certificate's issuer
limit_exceededA CRL or certificate exceeds a micro509 decoding limit, see ParseCertificateRevocationListErrorCode
non_applicableNo supplied CRL applies to the certificate (RFC 5280 §6.3.3)
signature_invalidCRL signature fails against the issuer key
stale_crlCRL outside its thisUpdate/nextUpdate window or older than maxAgeMs
unsupportedA CRL or certificate holds a value micro509 does not decode, see ParseCertificateRevocationListErrorCode

A non_applicable failure carries a reason. delta_crl_incompatible covers a delta CRL that does not pair with the complete CRL, including one whose thisUpdate precedes the complete CRL's thisUpdate.

ValidateOcspResponseErrorCode ​

CodeMeaning
issuer_mismatchCertID does not hash to the supplied issuer
limit_exceededA response, request or certificate exceeds a micro509 decoding limit, see ParseOcspResponseErrorCode
next_update_missingA response omits nextUpdate under profile: 'rfc9919' (RFC 9919 §5)
nonce_mismatchResponse nonce differs from the request's
ocsp_signing_missingDelegated responder lacks the ocspSigning EKU
request_mismatchResponse does not answer every requested CertID
responder_chain_invalidResponder certificate path fails validation
responder_id_mismatchResponderID matches no candidate signer
responder_revocation_unknownDelegated responder revocation status undetermined
responder_revokedDelegated responder certificate is revoked
response_status_invalidOCSPResponse status is not successful
signature_invalidResponse signature fails
stale_responseResponse outside its freshness window
unsupportedA response, request or certificate holds a value micro509 does not decode, see ParseOcspResponseErrorCode

CheckCertificateRevocationErrorCode ​

CodeMeaning
limit_exceededThe certificate exceeds a micro509 decoding limit, see ParseCertificateErrorCode
revocation_evidence_missingNo CRL or OCSP evidence was supplied
revocation_status_indeterminateEvidence yielded no verdict under the hard-fail policy
unsupportedThe certificate holds a value micro509 does not decode, see ParseCertificateErrorCode

RevocationIndeterminateReasonCode ​

CodeMeaning
certificate_status_missingResponse carries no entry for the certificate
certificate_status_unknownResponder answered unknown
crl_sign_not_permittedCRL signer's keyUsage lacks cRLSign, or a v3 signer has no keyUsage
issuer_mismatchEvidence issuer does not match the certificate's issuer
limit_exceededEvidence or a certificate it names exceeds a micro509 decoding limit
next_update_missingOCSP response omits nextUpdate under ocspProfile: 'rfc9919'
non_applicableNo supplied CRL applies to the certificate
nonce_mismatchResponse nonce differs from the request's
ocsp_signing_missingDelegated responder lacks the ocspSigning EKU
reason_coverage_incompleteApplicable CRLs cover only some CRLReasons
request_mismatchResponse does not answer the supplied request
responder_chain_invalidResponder certificate path fails validation
responder_id_mismatchResponderID matches no candidate signer
responder_revocation_unknownDelegated responder revocation status undetermined
responder_revokedDelegated responder certificate is revoked
response_status_invalidOCSPResponse status is not successful
signature_invalidEvidence signature fails
stale_crlCRL outside its thisUpdate/nextUpdate window or older than crlMaxAgeMs
stale_responseResponse outside its freshness window
unsupportedEvidence or a certificate it names holds a value micro509 does not decode

The chain-level RevocationIndeterminateReason from checkChainRevocation and verifyCertificateChain({ revocation }) uses its own names. A CRL that is outside its window or older than crlMaxAgeMs is reported as crl_expired, and an OCSP response without nextUpdate under ocspProfile: 'rfc9919' as ocsp_next_update_missing.

CrlEncoderErrorCode ​

CodeMeaning
distribution_point_full_name_emptyIDP fullName present but holds no GeneralName
issuer_distinguished_name_emptyRFC 5280 §5.1.2.3 requires a non-empty issuer DN
invalid_dateA CRL or revoked-entry date is an invalid Date
next_update_not_after_this_updatenextUpdate does not encode a later second than thisUpdate

OcspEncoderErrorCode ​

CodeMeaning
invalid_dateA response date is an invalid Date
signer_certificate_key_mismatchSigner certificate's SPKI does not match the signing key

micro509/keys ​

ImportKeyErrorCode ​

CodeMeaning
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedKey material fails to parse or match the request

ImportEncryptedKeyErrorCode ​

CodeMeaning
invalid_passwordDecryption failed, or plaintext is not a private key
kdf_iterations_exceededPBKDF2 iteration count exceeds maxKdfIterations (2,000,000 default)
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedEnvelope fails to parse before any decryption, including a PBKDF2 iterationCount outside 1 to 4294967295 whatever maxKdfIterations allows

EncryptRsaOaepErrorCode ​

CodeMeaning
invalid_keyKey is not an RSA-OAEP public key with encrypt usage
message_too_longPlaintext exceeds the OAEP capacity of the key

DecryptRsaOaepErrorCode ​

CodeMeaning
decryption_failedDeliberately opaque: wrong key, wrong label, or bad ciphertext
invalid_keyKey is not an RSA-OAEP private key with decrypt usage

micro509/pem ​

PemErrorCode ​

CodeMeaning
malformedEncapsulation or base64 violates RFC 7468 strict mode

micro509/der ​

DecodeDerErrorCode ​

CodeMeaning
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedBytes are not the expected DER structure
unsupportedA TeletexString holds an octet outside the X.690 §8.23.5.2 initial state, which micro509 does not decode

micro509/pkcs ​

ParsePfxErrorCode ​

CodeMeaning
invalid_passwordMAC or decryption rejects the supplied password
kdf_iterations_exceededThe PBES2 bags' combined PBKDF2 iteration counts exceed maxKdfIterations (2,000,000 default), or the MAC's count exceeds its own maxKdfIterations (100,000 default for the PKCS#12 KDF, 2,000,000 for PBMAC1)
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER or BER nested deeper than 64 levels
malformedPFX structure fails to parse, including a PBKDF2 iterationCount outside 1 to 4294967295 in a PBES2 bag or a PBMAC1 MAC
password_not_bmp_stringThe RFC 7292 MAC password (macPassword, or password as fallback) contains a UTF-16 surrogate, U+FFFE or U+FFFF
password_not_utf8The PBMAC1 password contains an unpaired UTF-16 surrogate
password_requiredEncrypted content present but no password given
unsupportedA certBag certificate's TeletexString name value holds an octet outside the X.690 §8.23.5.2 initial state, which micro509 does not decode
unsupported_mac_algorithmThe MAC is neither the SHA-256 RFC 7292 MAC nor a supported PBMAC1 variant
weak_mac_key_lengthPBMAC1 PBKDF2 keyLength is below 20 octets

CreatePfxErrorCode ​

CodeMeaning
invalid_certificateA certificate source fails to parse

PfxEncoderErrorCode ​

createPfx throws this as a ResultError.

CodeMeaning
invalid_friendly_nameA bag friendlyName is not a BMPString of 1 to 255 characters (RFC 2985 §5.5.1)

CreatePkcs12MacDataErrorCode ​

createPkcs12MacData, and createPfx through its mac option, throw these as a ResultError.

CodeMeaning
invalid_iterationsiterations is not a positive safe integer (RFC 7292 MAC) or not an integer from 1 to 4294967295 (PBMAC1)
password_not_bmp_stringRFC 7292 MAC password contains a UTF-16 surrogate, U+FFFE or U+FFFF
password_not_utf8PBMAC1 password contains an unpaired UTF-16 surrogate

ParsePkcs12MacDataErrorCode ​

CodeMeaning
kdf_iterations_exceededWith a password, the iteration count exceeds maxKdfIterations (100,000 default for the PKCS#12 KDF, 2,000,000 for PBMAC1), or an RFC 7292 MAC count exceeds Number.MAX_SAFE_INTEGER
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedMacData structure fails to parse, an iteration count is below 1, a PBMAC1 count exceeds 4294967295 whatever maxKdfIterations allows, or, without a password, an RFC 7292 MAC count exceeds Number.MAX_SAFE_INTEGER
password_not_bmp_stringRFC 7292 MAC password contains a UTF-16 surrogate, U+FFFE or U+FFFF
password_not_utf8PBMAC1 password contains an unpaired UTF-16 surrogate
unsupported_mac_algorithmThe MAC is neither the SHA-256 RFC 7292 MAC nor a supported PBMAC1 variant
weak_mac_key_lengthPBMAC1 PBKDF2 keyLength is below 20 octets

Without a password no key is derived. maxKdfIterations is not applied, and verification is 'unchecked' for any RFC 7292 MAC count from 1 to Number.MAX_SAFE_INTEGER and any PBMAC1 count from 1 to 4294967295.

ParsePkcs7ErrorCode ​

CodeMeaning
limit_exceededA micro509 limit: an OBJECT IDENTIFIER sub-identifier encoded in more than 64 octets, a tag number of 2^53 or more, or DER nested deeper than 64 levels
malformedContentInfo or SignedData fails to parse
not_signed_dataContentInfo carries a content type other than data
unsupportedA signer issuer TeletexString value holds an octet outside the X.690 §8.23.5.2 initial state, which micro509 does not decode

CreatePkcs7CertBagErrorCode ​

CodeMeaning
invalid_certificateA certificate source fails to parse
limit_exceededA certificate exceeds a micro509 decoding limit, see ParseCertificateErrorCode
unsupportedA certificate holds a value micro509 does not decode, see ParseCertificateErrorCode

CreatePkcs7SignedDataErrorCode ​

CodeMeaning
invalid_certificateAn additionalCertificates entry fails to parse
invalid_signer_certificateA signer's certificate source fails to parse
limit_exceededA signer or additional certificate exceeds a micro509 decoding limit, see ParseCertificateErrorCode
no_signerssigners is empty
signer_certificate_key_mismatchSigner certificate's SPKI does not match the signing key
unsupported_signer_keySigning key algorithm has no CMS digest mapping
unsupportedA signer or additional certificate holds a value micro509 does not decode, see ParseCertificateErrorCode

VerifyPkcs7SignedDataErrorCode ​

CodeMeaning
detached_content_requiredSignedData has no eContent and no content option supplied
limit_exceededA micro509 limit while parsing, see ParsePkcs7ErrorCode
malformedStructure, attributes, or algorithms fail to process
message_digest_mismatchContent digest differs from the messageDigest attribute
no_signerssignerInfos is empty
not_signed_dataContentInfo carries a content type other than SignedData
signature_invalidA signer's signature does not verify
signer_not_foundNo embedded certificate matches a SignerInfo
unsupportedA signer issuer value micro509 does not decode, see ParsePkcs7ErrorCode

Released under the MIT License.