Skip to main content

Cascade Administration

Run the CMS itself — who gets in and what they can do, how Sites are organized, the tools for logs and the database, and the Connectors that tie Cascade CMS to other systems.

Where to start

1

Decide who can do what

Permissions split into two spheres: the abilities a Role grants across the system, and the access a user or group has to a specific folder.

Permissions →
2

Add the people

Create users, put them in groups, and give each one a Role — plus how to log in as someone else to reproduce what they are seeing.

Users →
3

Organize the content

A Site is the container for everything an audience's content needs. Create one, copy one, or move one between installations.

Sites →

Access and accounts

1

Choose how users sign in

Normal, LDAP, and custom authentication, and what each one means for where passwords live.

Authentication →
2

Know what a Role can reach

The full list of abilities a Role can grant or withhold, from asset actions to administrative areas.

Role Abilities →
3

See who changed something

Audits record the actions taken in the system, filterable by user, asset, action, and date.

Audits →

Keeping the system healthy

1

Look at what the system is doing

Download log files, check the runtime environment, and post an announcement to everyone currently working in the CMS.

Administration Tools →
2

Maintain the database

Optimize the database, and export it when you need a copy outside the application.

Database Tools →
3

Set the system-wide defaults

System Preferences control behavior for every Site at once — naming rules, editor defaults, link checking, and more.

System Preferences →

Connecting other systems

1

See what Connectors can do

Connectors tie Cascade CMS to third-party services — analytics, content export, DAM libraries, and web governance platforms.

Connectors and Integrations →
2

Catch problems before publishing

Web governance Connectors surface accessibility, link, spelling, and SEO findings on the asset that caused them.

Web Governance →
3

Report on traffic in the CMS

An Analytics Connector brings basic traffic figures onto the Sites, pages, files, and folders authors already work in.

Analytics →

All Articles

"Could not acquire change log lock" or "Waiting for changelog lock..."

During start-up, one of the following messages may appear in the cascade.log file and prevent Cascade CMS from starting: Waiting for changelog lock....

"Remember Me" Cookied Login Vulnerabilities

Weaknesses identified in the Cascade CMS cookied login process that could allow an attacker to access the CMS as another user, and the versions that remediate them.

Access Rights

Access Rights are the permissions that control which Users or Groups can view or change Assets. Each asset has Access Rights assigned.

Acquia DAM (Widen) Integration (Labs)

Enable the Acquia DAM (Widen) Labs integration so authors can browse and place assets from a Widen Collective library inside the WYSIWYG editor.

Add or remove the Windows service

Install or remove the Windows service that runs a self-hosted Cascade CMS instance.

Administration Menus

Where the administrator-facing areas live: the system menu, and what each entry under Administration covers.

Administration Tools

The system-level tools for messaging active users, downloading log files, and turning on extra logging while troubleshooting.

Analytics

Analytics Connectors pull traffic data from a third-party analytics account into Cascade CMS, so authors see how a page performs without leaving the CMS.

Announcements

Announcements allow administrators to create and display messages to users working in the CMS.

Audits

Audits allow administrators to see a summary of activities performed in Cascade CMS by a particular User, Group, or Role or on a particular asset.

Authentication

Cascade CMS can authenticate users natively, through an external LDAP server, or via custom authentication.

Cascade CMS 8 Upgrade Prep Guide

What to clean up before upgrading to Cascade CMS 8: Global area content, unassigned Content Types, and a database check.

Common Error Messages

Specific error messages you may hit in Cascade CMS — in the logs, on submit, while publishing, or during rendering — and how to resolve each one.

Comparison method violates its general contract

Why a Velocity or XSLT sort throws "Comparison method violates its general contract", and how to guard against items missing the value being sorted on.

Configure a web server for publishing

What a web server needs to serve content published from Cascade CMS, and how the publishing Destination reaches it.

Configuring Cascade CMS Log Rotation and Compression

This article is provided as an example of how to configure Cascade CMS application logging to use rotation and/or compression.

Configuring Cascade CMS to point to a Java installation

This article describes the necessary steps to point Cascade CMS to a Java installation.

Configuring outbound proxy support for system-generated emails

This article shows how to configure your Cascade CMS environment to send emails if you're using an outbound proxy .

Configuring the Heap Dump on Out of Memory option

This article contains steps on capturing heap dumps from the application. These can be useful for troubleshooting memory problems.

Connectors and Integrations

Connectors and integrations allow you to utilize third-party applications and tools within Cascade CMS.

Content Export

Content Export Connectors push content managed in Cascade CMS out to another system, so a page can be authored once and delivered elsewhere.

Could not create index writer

How to clear a stale Lucene write.lock when Cascade CMS logs "Could not create index writer" and cannot build its search index.

Could not get file content for lucene indexing

What the "Could not get file content for lucene indexing" error means, and how to identify and clear the corrupt file that causes it.

Could not reset lucene directory

The "Could not reset lucene directory" error is caused by O/S account permissions on the Cascade CMS installation folder. Here is how to correct them.

Creating a database backup

This article shows some sample steps that can be used to create a database backup for all vendors

CVE-2020-1938 Ghostcat

How to secure the Tomcat AJP Connector bundled with Cascade CMS against CVE-2020-1938 (Ghostcat), for installations that have not yet upgraded to Cascade CMS 8.15.

CVE-2021-4104

Cascade CMS is not affected by CVE-2021-4104, the Log4j 1.x JMSAppender remote code execution flaw, plus steps for removing the affected class from older on-premise distributions.

CVE-2021-44228 Log4Shell

Cascade CMS is not affected by CVE-2021-44228 (Log4Shell), because the log4j message lookup substitution feature the exploit depends on is disabled or unsupported in our implementation.

CVE-2021-45046 Log4Shell

Cascade CMS is not affected by CVE-2021-45046, the incomplete fix for Log4Shell, plus steps for removing the JndiLookup class from older on-premise distributions.

CVE-2021-45105 Log4Shell

Cascade CMS is not affected by CVE-2021-45105, the Log4j self-referential lookup denial of service, because message lookup substitution is disabled or unsupported in our use of log4j.

CVE-2022-22965 Spring4Shell

Cascade CMS is not affected by CVE-2022-22965 (Spring4Shell) — it uses the Spring Framework for dependency injection but does not include the affected spring-mvc package.

CVE-2022-23302 JMSSink

Cascade CMS is not affected by CVE-2022-23302 — the Log4j 1.x JMSSink deserialization issue — because the affected sink is not referenced in our configuration.

CVE-2022-23305 JDBCAppender

Cascade CMS is not affected by CVE-2022-23305 — the Log4j 1.x JDBCAppender SQL injection issue — because the affected appender is not referenced in our configuration.

CVE-2022-23307 Chainsaw Package

Cascade CMS is not affected by CVE-2022-23307 — the Log4j 1.x Chainsaw deserialization issue — because the affected component is not referenced in our configuration.

CVE-2025-24813

Cascade CMS is not affected by CVE-2025-24813, the Apache Tomcat partial PUT path equivalence vulnerability, because the required settings are not enabled in our default installations.

CVE-2026-34477

Cascade CMS is not affected by CVE-2026-34477, the incomplete Log4j TLS hostname verification fix, because the default configuration doesn't use the affected appenders.

CVE-2026-34480

Cascade CMS is not affected by CVE-2026-34480, the Log4j XmlLayout invalid XML output issue, because the application doesn't use the affected Log4j implementation.

Database

Setting up the Cascade CMS database on MySQL, SQL Server, or Oracle, plus backups and keeping the database from growing without bound.

Database Export

Export the Cascade CMS database from the Administration area, and what to enable first when the database is SQL Server.

Database Size Management Tips

The overall size of your Cascade CMS database is dependent on a number of factors.

Database Tools

These tools allow system administrators to optimize, repair, and export the CMS database.

Diagnostics

Gathering the data a support investigation needs — log files, thread dumps, and HAR files — and where each one comes from.

Digital Asset Management (DAM)

DAM Connectors let authors browse a third-party asset library and place its images directly from the WYSIWYG editor, without downloading and re-uploading files.

DubBot Integration

Connect Cascade CMS to DubBot so its accessibility, broken link, spelling, and SEO findings can be fixed on the asset that caused them.

Enabling HTTP Strict Transport Security (HSTS)

This article provides steps for configuring HSTS in Cascade CMS.

Enabling or Disabling TLS Versions

This article contains steps for enabling or disabling certain versions of TLS.

Error constructing implementation

How to resolve the SSL/TLS "Error constructing implementation" error by checking Cascade CMS's key store configuration.

Error executing SQL DELETE FROM `cxml_history_item`

The following error message may appear when upgrading to Cascade 8 against a version of MySQL 5.7 prior to release 5.7.11: Migration failed for change set com/hannonhill/cascade/model/database/updater/updates/8_0/8_0_006.xml::8_0_006::artur.tomusiak: Reason: liquibase.exception.JDBCException: Error

Exception invoking method 'getAvailableIDs' in class sun.util.calendar.ZoneInfo

This particular error message is indicative of a missing startup parameter for the application.

External Link Checking Preferences

External Link Checking preferences allow administrators to configure system-wide external link checking behavior and functionality.

Firewall Considerations

This article contains information on inbound and outbound ports that the application will use.

Forcing connections to use SSL/TLS

Once the SSL/TLS connector has been enabled per these instructions, users may still be able to access the application through the default port 8080.

Generate a HAR file

Steps for capturing a HAR file of network activity for a support investigation, and how to redact it before sharing.

Generating a thread dump

How to capture a Java thread dump from Cascade CMS on Linux with kill -3, or on Windows with jcmd.

Google Analytics Connector

Set up the Google Analytics Connector so traffic figures from a Google Analytics 4 property appear on Sites, pages, files, and folders in Cascade CMS.

Granting Access to Specific Folders for Users/Groups

A worked example of hiding every Folder in a Site by default, then granting one Group access to just the Folder it needs.

Groups

A group is made up of one or more users with common permissions.

Header message of length [] received but the packetSize is only []

The AJP request header exceeds Tomcat's configured packetSize. Add a packetSize attribute to the connector in server.xml to resolve it.

How can I check what a User can do in a specific Site?

Use the Effective Abilities tool for a list of a user's abilities in a Site, or Assume Identity to see the system as they see it.

How can I enable request logging for Cascade CMS?

Add an AccessLogValve to tomcat/conf/context.xml to write a request log alongside the other Tomcat logs.

How can I find the O/S account running Cascade CMS?

The User Name field in Logs and System Information shows the account the application runs under.

How can I find which Java installation my Cascade CMS instance is using?

Check the JRE_HOME variable in the boot script for your platform, or read the JVM details from Logs and System Information.

How can I view the largest binary files within my database?

SQL queries for SQL Server, Oracle, and MySQL that list stored files from largest to smallest.

How do I change the name or URL of my site?

Update the Name and URL fields on the Properties tab of Site Settings.

How do I control User access to Folders and assets?

Set Access rights on an asset, and use Access for Contents to apply them down a Folder — merging rather than overwriting.

How do I delete a site?

Select the site in the Sites list and click Delete. Deleted sites cannot be restored.

How do I enable DEBUG logging?

Add a logging category or class at DEBUG level from the Logging Configuration tool, and reset it once you've collected what you need.

How do I give a User or Group access to a Site?

Assign a Site Role on the Roles tab of Site Settings, and make sure the user has Read access to the Site's Base Folder.

How do I rebuild my search indexes?

Trigger a search index rebuild from Administration > Search Indexing, and what to expect in the log and the Background Tasks Report while it runs.

Installation and Upgrades

Installing, upgrading, and moving a self-hosted Cascade CMS instance — installers per platform, the database, server configuration, and migration.

Installation/Upgrade (macOS)

Install or upgrade a self-hosted Cascade CMS instance on macOS using the graphical installer.

Installation/Upgrade (Windows)

Install or upgrade a self-hosted Cascade CMS instance on Windows, including the Windows service and command-line options.

Installation/Upgrade (ZIP)

Install or upgrade a self-hosted Cascade CMS instance from the ZIP distribution on Linux, macOS, or Windows.

Invalid XML character was found in the element content of the document

An "invalid XML character" error on submit means a control character was pasted into a WYSIWYG field. Here is how to find and remove it.

Invalid XML: The prefix "o" for element "o:p" is not bound

If you receive this error when trying to create or submit changes to an asset, there may be <o:p> tags in the source code of your editor that will need to be removed or converted to regular <p> tags before the asset can be submitted.

LDAP/Active Directory Authentication

Authenticating users against an existing LDAP or Active Directory server: connection options, policies, orphaned users, and the XML that configures it.

Load Balancing

Run Cascade CMS behind a load balancer: Tomcat and Apache configuration, cache synchronization, and what to check when sessions misbehave.

Logging Configuration

This section of the Administration area provides system administrators with the ability to configure additional logging for troubleshooting purposes.

Login Failed

This article describes steps that Administrators can take to troubleshoot failed login attempts for their users.

Logs and System Information

Download application log files and check the environment Cascade CMS is running in — memory, JVM settings, operating system, and version.

Migrating Cascade CMS to a new server

Move a self-hosted Cascade CMS instance to a new server: what to copy, what to reconfigure, and what to verify.

Migration Tool

Use the Universal Migration Tool to bring content from an existing site into Cascade CMS, mapping folders, Content Types, and fields.

Modifying Application Ports

This article outlines steps for changing the default port settings for the application.

Modifying the Database Configuration

This article contains steps to configure the database connection settings for the application

Modifying the Heap Size

This article contains the steps needed to modify the minimum (Xms) and maximum (Xmx) heap size for the application.

Modifying the Thread Stack Size

This article contains steps for configuring the Thread Stack Size for the application.

Monsido Integration

Pair a Monsido account with Cascade CMS and the Monsido Chrome extension so Monsido findings appear over the CMS interface.

MySQL 8: Public Key Retrieval is not allowed

Resolve the Public Key Retrieval error after upgrading to MySQL 8 in Cascade CMS.

MySQL: Can't create table

When starting Cascade CMS for the first time or after importing a new MySQL database, administrators may see an error message in the log file similar to the following: ERROR [StartupTasks] : *** Startup task: DatabaseIndexAndKeyManagerfailed to execute successfully: java.sql.SQLException: Can't crea

MySQL: Can't create/write to file

Organizations using MySQL may see an error message similar to the following when attempting to login to the system: Login failed: An error occurred: Startup task: DatabaseIndexAndKeyManager failed to execute successfully: java.sql.SQLException: Can't create/writeto file 'C:\WINNT\TEMP\#sql_718_0.MYI

Optimize Database

The Optimize Database tool removes and/or repairs various records within the database. It is NOT recommended to run this tool frequently.

ORA-22275: invalid LOB locator specified

Oracle users may encounter this error when attempting to copy, edit, or submit assets in the system.

Packet for query is too large

Resolve the MySQL max_allowed_packet error when uploading files into Cascade CMS.

PageRenderException: Could not transform with Script format

When previewing a page, you may see a full-page error of the type Could not transform with Script format...

Parameters missing

This article describes steps to take when you receive a 'Parameters missing' error while attempting to submit a file or page.

Permissions

The two spheres of permissions in Cascade CMS: system-wide abilities granted by a Role, and Site-level access to what a user can see and do.

Permissions in Cascade CMS: Sites, Roles, Groups, and Folder Access

Understand how site access, roles, groups, and folder-level permissions work together in Cascade CMS, with a practical decision matrix and troubleshooting guide.

Role Abilities

Every ability a System Role or Site Role can grant, grouped by the area of Cascade CMS it applies to.

Roles

A role is a set of a abilities that govern a user's access to a number of different areas in Cascade CMS.

Running Cascade CMS as a Linux service

This article contains samples using systemd and init.d service files.

Search and Indexing

Keeping Cascade CMS search working — rebuilding indexes, diagnosing missing results, granting access to Full Search, and the error messages the indexer produces.

Search failed: no segments file found

The "Search failed: no segments file found" error is resolved by rebuilding the Cascade CMS search indexes.

Search isn't returning expected results

Work through the Build Search Index task in the Background Tasks Report — its Status and Duration tell you whether the index built, stalled, or hit a permissions problem.

Secure LDAP sync fails after upgrade to Cascade CMS v8.11

Cascade CMS v8.11 comes bundled with a newer version of Java (JRE 8u191).

Securing session cookies

Mark the Cascade CMS session cookie secure and HttpOnly so it is only sent over TLS and is not readable from scripts.

Security Advisories

Hannon Hill's assessments of published CVEs and other security issues as they relate to Cascade CMS, including whether Cascade Cloud and on-premise installations are affected.

Setting up a test environment

Stand up a test copy of a Cascade CMS instance without letting it publish, email, or talk to connected services.

Setting up the database (MySQL)

Set up the Cascade CMS database on MySQL: install the server, adjust its configuration, and import the supplied database.

Setting up the database (Oracle)

Set up the Cascade CMS database on Oracle: create a tablespace and import the supplied database.

Setting up the database (SQL Server)

Set up the Cascade CMS database on SQL Server: attach the supplied database and set its isolation level to snapshot.

Site Import and Export

Cascade CMS supports the transfer of content and administrative properties from one Cascade CMS environment to another by way of exporting and importing Sites.

Siteimprove Integration

Cascade CMS's Siteimprove plugin allows existing Siteimprove customers to access data from the Siteimprove Intelligence Platform from within the CMS.

Sites

Sites are containers for organizing all content and administrative assets and properties for a website in Cascade CMS.

Snippets

With Snippets, your team can quickly create, update, and reuse standardized content elements throughout your site without any technical expertise.

Sorry, workflow is required to be able to continue but no workflows are available to you.

This error means that the user's Site Role doesn't allow them to Bypass workflow, but there isn't an applicable workflow available for the type of action they're taking.

SSL/TLS Configuration

Configuring SSL/TLS for the application requires two steps (as described in the official Tomcat documentation): Creating/preparing the Java keystore.

System Configuration

Configuring the application server behind a self-hosted Cascade CMS instance: memory and ports, TLS, logging, proxying, load balancing, and the license key.

System Dictionary

Add words to the system dictionary so the spell checker stops flagging them, export the dictionary, and copy a legacy user dictionary.

System Preferences

System preferences allow administrators to configure system-wide properties such as email, link checking, and content settings.

Table headers are poorly structured

How to clear the "Table headers are poorly structured" accessibility error by setting the correct cell type and scope on a table's header cells.

The driver could not establish a secure connection to SQL Server by using Secure Sockets Layer (SSL) encryption

When attempting to start Cascade CMS, organizations using SQL Server may be presented with the following error in the log files (which prevents the application from starting): ("encrypt" property is set to "true" and "trustServerCertificate" property is set to "false" but the driver could not establ

The driver could not establish a secure connection to SQL Server by using Secure Sockets Layer (SSL) encryption. Error: "Unexpected rethrowing"

This particular error message can appear on startup.

The index block with path {path} renders too much data

This message is displayed when an Index Block in the system renders a large amount of data and reaches the limit configured in the system Preferences.

Updating the license key

This article contains information on updating the license key.

Upgrading Tomcat independently of Cascade CMS

This article describes the steps needed in order to upgrade the bundled Tomcat installation

Users

Add users, apply password policies, check the abilities a user effectively has, and assume a user's identity to see what they see.

Using Apache 2.4 to proxy Cascade CMS

This article is provided as an example of using Apache 2.4 to to proxy Cascade CMS.

Web Governance

Web governance Connectors surface accessibility, broken link, spelling, and SEO findings from a third-party platform inside Cascade CMS.

Where can I find the Cascade CMS log files?

Log files are available from Logs and System Information in the Administration area, or in the tomcat/logs directory on the server.

Why can't my user upload images in the WYSIWYG or file chooser?

The Upload tab requires the Upload images in file chooser Site Role ability, and on versions before 8.22 also Bypass workflow.

Why can't my users access the full search feature?

Full Search and Replace lives in the Administration area, so users need a System Role with Access Administration Area enabled.

Why can't my users see anything in the Add Content menu?

An Asset Factory appears in Add Content only when the user's Group is listed in Applicable Groups on both the Asset Factory and its Container.

WordPress Connector

Set up a WordPress Connector so pages managed in Cascade CMS publish into a WordPress site.

Your roles do not allow you to advance workflow

This error indicates that the user's Site Role doesn't allow them to assign a Workflow to themselves or approve steps in a Workflow.