Validate error reference
The Validate operation returns errors as inline result codes or SOAP faults depending on the nature of the error.
Result codes
The following result codes are returned inline in the Result element of a Validate response. All other errors are returned as SOAP faults.
| Code | Description (Desc) | Details |
|---|---|---|
| OK | The signature is valid | The signature is valid. This also includes that the signer certificate is valid. |
| SignatureInvalid | <Descriptive message> | A signature or a timestamp is invalid. |
| SignerInvalid | <Descriptive message> | A signing certificate or a timestamp certificate is invalid; it is either revoked or expired. |
SOAP faults
The following SOAP faults can be returned by the Validate operation. Each fault includes a FaultCode and a Reason (FaultString) with a human-readable message.
| FaultCode | Reason | Description |
|---|---|---|
| Client | Not authorized | No client SSL certificate was used for authentication, or the client SSL certificate is not authorized for validation operations. |
| Client | Document input parameter only allowed for input type PKCS7D | The Document request parameter was specified for a signature type other than PKCS7D. |
| Client | Missing data in Document input parameter for input type PKCS7D | The Document request parameter was missing for a signature of type PKCS7D. |
| Client | Cannot locate signer certificate | The signer certificate of an IDEAL or GS1AT message cannot be found in the TrustWeaver database. |
| Client | SenderTag is required | No SenderTag is present in the Validate SOAP request, or the SenderTag cannot be parsed from the business document. |
| Client | ReceiverTag is required | No ReceiverTag is present in the Validate SOAP request, or the ReceiverTag cannot be parsed from the business document. |
| Client | No document present in request | No SignedDocument to be validated is present in the request. |
| Client | Signed content not present | No signed content can be parsed from the signature. |
| Client | Document corrupt | The format of the document parsed from the signature is corrupt. |
| Client | Could not find compliance map for <key reference> | The authentication certificate does not have any assigned compliance map. |
| Client | Could not find any validation policies for sender=<SenderTag> and receiver=<ReceiverTag> | It was not possible to derive a validation policy from the SenderTag/ReceiverTag pair. |
| Client | AgreementIdentifier format violation | The AgreementIdentifier is too long or contains illegal characters. |
| Client | ClientData format violation | The ClientData is too long or contains illegal characters. |
| Client | Validation policy mismatch for policies='<PolicyOID>' and receiver='<ReceiverTag>', sender='<SenderTag>' | The configured signing certificate policies of the requested SenderTag/ReceiverTag pair do not match the signer(s) of the signed business document. |
| Client | Illegal combination: <jobType>/<inputType> | There are restrictions on how to combine JobType with InputType. See the JobType reference for details. |
| Client | Illegal InputType/OutputType combination | Not all combinations of InputType and OutputType are allowed. See the supported formats reference for details. |
| Client | InputType <inputType value> does not match input document type | The InputType is set to a supported value, but the document to be validated is completely malformed and cannot be parsed. Note that "Document is not PDF," "Signature corrupt," and "Document corrupt" errors have separate codes. |
| Client | Insufficient space for validation data in pdf | The signed PDF provided as input does not have enough allocated space to fit a CAdES-A signature. |
| Client | Authentication certificate not configured | The client certificate used has not been configured to access this operation. |
| Client | Document size (<actualSize> bytes) exceeded the maximum allowed size (<maxSize> bytes) | The size of the uploaded document exceeds the maximum allowed size for the InputType/OutputType combination in use. |
| Client | ISO9796-2 unknown trailer '<X>' | The ISO9796-2 trailer was not recognized. |
| Client | ISO9796-2 implicit trailer not allowed | Implicit trailer is not allowed for ISO9796-2. |
| Client | ISO9796 trailer mismatch, expected '<X>' but was '<Y>' | The hash algorithm specified in the ISO9796-2 trailer (<Y>) is not the expected one (<X>). |
| Client | Signing certificate has unsupported asymmetric algorithm <oid> | An asymmetric algorithm other than RSA was used to create the signature. |
| Client.NotAuthorized | Authentication certificate not found, revoked or not valid | The client certificate used has not been configured to access this operation. |
| Server | Internal server error | General server exception. |
