Troubleshooting: "IDX10000" Null-Parameter Exceptions

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    This article explains two causes of an "IDX10000: The parameter '<name>' cannot be a 'null' or an empty object" exception.

    • See Cause 1 - If this occurs on an OpenID realm as a server_error, with the parameter named certificate.
    • See Cause 2 - If this occurs after migrating to a 19.07 or later appliance, with the parameter named jwtEncodedString.

    These causes are not related, so a fix for one cause will not resolve the other cause.

     

    In this article


     

    Cause 1: No Signing Certificate Selected (OpenID Realm)

    When setting up an OpenID realm, signing in can show a server_error. The Debug log shows: "[AuthorizeEndpoint].[ProcessConsent]: Exception: System.ArgumentNullException: IDX10000: The parameter 'certificate' cannot be a 'null' or an empty object." This occurs because no certificate is selected for the signing certificate on the realm's Post Authentication tab. A certificate must be selected even if it isn't actually being used for signing.

     

    Resolution 1:

    To resolve this:

    1. On the realm's Post Authentication tab, select a signing certificate.

     

    Cause 2: Client Certificate Mismatch After Migration (19.07 and Later)

    After migrating to a new appliance stood up on 19.07 or later, affected realms can show "Error Retrieving Contact Information" when logging in, or SMS/Voice MFA can fail with "Unable to use selected registration method, please choose another method" — hovering over the error shows "Exception: IDX10000: The parameter 'jwtEncodedString' cannot be a 'null' or an empty object." This occurs because the client certificate used in the realm, post-migration, differs from the one originally pulled down with the new tenant.

     

    Resolution 2:

    To resolve this:

    1. In the Admin Console (Classic View), open the affected realm and go to the System Info tab.
    2. Scroll to the SecureAuth Cloud Services section.
    3. Click Client Cert Serial Nbr, select the other available certificate, and save.



     

    Special Considerations

    If only some realms are affected and others are not, mismatched MFC.SecureAuth.License.dll files between realms may be the reason — this can cause the appliance to throw the error for realms whose license file does not match the client certificate it expects to use.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.