Cascade Administration
Run the CMS itself — who gets in and what they can do, how Sites are organized, the tools for logs and the database, and the Connectors that tie Cascade CMS to other systems.
Where to start
Decide who can do what
Permissions split into two spheres: the abilities a Role grants across the system, and the access a user or group has to a specific folder.
Permissions →Add the people
Create users, put them in groups, and give each one a Role — plus how to log in as someone else to reproduce what they are seeing.
Users →Organize the content
A Site is the container for everything an audience's content needs. Create one, copy one, or move one between installations.
Sites →Access and accounts
Choose how users sign in
Normal, LDAP, and custom authentication, and what each one means for where passwords live.
Authentication →Know what a Role can reach
The full list of abilities a Role can grant or withhold, from asset actions to administrative areas.
Role Abilities →See who changed something
Audits record the actions taken in the system, filterable by user, asset, action, and date.
Audits →Keeping the system healthy
Look at what the system is doing
Download log files, check the runtime environment, and post an announcement to everyone currently working in the CMS.
Administration Tools →Maintain the database
Optimize the database, and export it when you need a copy outside the application.
Database Tools →Set the system-wide defaults
System Preferences control behavior for every Site at once — naming rules, editor defaults, link checking, and more.
System Preferences →Connecting other systems
See what Connectors can do
Connectors tie Cascade CMS to third-party services — analytics, content export, DAM libraries, and web governance platforms.
Connectors and Integrations →Catch problems before publishing
Web governance Connectors surface accessibility, link, spelling, and SEO findings on the asset that caused them.
Web Governance →Report on traffic in the CMS
An Analytics Connector brings basic traffic figures onto the Sites, pages, files, and folders authors already work in.
Analytics →All Articles
"Could not acquire change log lock" or "Waiting for changelog lock..."
During start-up, one of the following messages may appear in the cascade.log file and prevent Cascade CMS from starting: Waiting for changelog lock....
"Remember Me" Cookied Login Vulnerabilities
Weaknesses identified in the Cascade CMS cookied login process that could allow an attacker to access the CMS as another user, and the versions that remediate them.
Access Rights
Access Rights are the permissions that control which Users or Groups can view or change Assets. Each asset has Access Rights assigned.
Acquia DAM (Widen) Integration (Labs)
Enable the Acquia DAM (Widen) Labs integration so authors can browse and place assets from a Widen Collective library inside the WYSIWYG editor.
Add or remove the Windows service
Install or remove the Windows service that runs a self-hosted Cascade CMS instance.
Administration Menus
Where the administrator-facing areas live: the system menu, and what each entry under Administration covers.
Administration Tools
The system-level tools for messaging active users, downloading log files, and turning on extra logging while troubleshooting.
Analytics
Analytics Connectors pull traffic data from a third-party analytics account into Cascade CMS, so authors see how a page performs without leaving the CMS.
Announcements
Announcements allow administrators to create and display messages to users working in the CMS.
Audits
Audits allow administrators to see a summary of activities performed in Cascade CMS by a particular User, Group, or Role or on a particular asset.
Authentication
Cascade CMS can authenticate users natively, through an external LDAP server, or via custom authentication.
Cascade CMS 8 Upgrade Prep Guide
What to clean up before upgrading to Cascade CMS 8: Global area content, unassigned Content Types, and a database check.
Common Error Messages
Specific error messages you may hit in Cascade CMS — in the logs, on submit, while publishing, or during rendering — and how to resolve each one.
Comparison method violates its general contract
Why a Velocity or XSLT sort throws "Comparison method violates its general contract", and how to guard against items missing the value being sorted on.
Configure a web server for publishing
What a web server needs to serve content published from Cascade CMS, and how the publishing Destination reaches it.
Configuring Cascade CMS Log Rotation and Compression
This article is provided as an example of how to configure Cascade CMS application logging to use rotation and/or compression.
Configuring Cascade CMS to point to a Java installation
This article describes the necessary steps to point Cascade CMS to a Java installation.
Configuring outbound proxy support for system-generated emails
This article shows how to configure your Cascade CMS environment to send emails if you're using an outbound proxy .
Configuring the Heap Dump on Out of Memory option
This article contains steps on capturing heap dumps from the application. These can be useful for troubleshooting memory problems.
Connectors and Integrations
Connectors and integrations allow you to utilize third-party applications and tools within Cascade CMS.
Content Export
Content Export Connectors push content managed in Cascade CMS out to another system, so a page can be authored once and delivered elsewhere.
Could not create index writer
How to clear a stale Lucene write.lock when Cascade CMS logs "Could not create index writer" and cannot build its search index.
Could not get file content for lucene indexing
What the "Could not get file content for lucene indexing" error means, and how to identify and clear the corrupt file that causes it.
Could not reset lucene directory
The "Could not reset lucene directory" error is caused by O/S account permissions on the Cascade CMS installation folder. Here is how to correct them.
Creating a database backup
This article shows some sample steps that can be used to create a database backup for all vendors
CVE-2020-1938 Ghostcat
How to secure the Tomcat AJP Connector bundled with Cascade CMS against CVE-2020-1938 (Ghostcat), for installations that have not yet upgraded to Cascade CMS 8.15.
CVE-2021-4104
Cascade CMS is not affected by CVE-2021-4104, the Log4j 1.x JMSAppender remote code execution flaw, plus steps for removing the affected class from older on-premise distributions.
CVE-2021-44228 Log4Shell
Cascade CMS is not affected by CVE-2021-44228 (Log4Shell), because the log4j message lookup substitution feature the exploit depends on is disabled or unsupported in our implementation.
CVE-2021-45046 Log4Shell
Cascade CMS is not affected by CVE-2021-45046, the incomplete fix for Log4Shell, plus steps for removing the JndiLookup class from older on-premise distributions.
CVE-2021-45105 Log4Shell
Cascade CMS is not affected by CVE-2021-45105, the Log4j self-referential lookup denial of service, because message lookup substitution is disabled or unsupported in our use of log4j.
CVE-2022-22965 Spring4Shell
Cascade CMS is not affected by CVE-2022-22965 (Spring4Shell) — it uses the Spring Framework for dependency injection but does not include the affected spring-mvc package.
CVE-2022-23302 JMSSink
Cascade CMS is not affected by CVE-2022-23302 — the Log4j 1.x JMSSink deserialization issue — because the affected sink is not referenced in our configuration.
CVE-2022-23305 JDBCAppender
Cascade CMS is not affected by CVE-2022-23305 — the Log4j 1.x JDBCAppender SQL injection issue — because the affected appender is not referenced in our configuration.
CVE-2022-23307 Chainsaw Package
Cascade CMS is not affected by CVE-2022-23307 — the Log4j 1.x Chainsaw deserialization issue — because the affected component is not referenced in our configuration.
CVE-2025-24813
Cascade CMS is not affected by CVE-2025-24813, the Apache Tomcat partial PUT path equivalence vulnerability, because the required settings are not enabled in our default installations.
CVE-2026-34477
Cascade CMS is not affected by CVE-2026-34477, the incomplete Log4j TLS hostname verification fix, because the default configuration doesn't use the affected appenders.
CVE-2026-34480
Cascade CMS is not affected by CVE-2026-34480, the Log4j XmlLayout invalid XML output issue, because the application doesn't use the affected Log4j implementation.
Database
Setting up the Cascade CMS database on MySQL, SQL Server, or Oracle, plus backups and keeping the database from growing without bound.
Database Export
Export the Cascade CMS database from the Administration area, and what to enable first when the database is SQL Server.
Database Size Management Tips
The overall size of your Cascade CMS database is dependent on a number of factors.
Database Tools
These tools allow system administrators to optimize, repair, and export the CMS database.
Diagnostics
Gathering the data a support investigation needs — log files, thread dumps, and HAR files — and where each one comes from.
Digital Asset Management (DAM)
DAM Connectors let authors browse a third-party asset library and place its images directly from the WYSIWYG editor, without downloading and re-uploading files.
DubBot Integration
Connect Cascade CMS to DubBot so its accessibility, broken link, spelling, and SEO findings can be fixed on the asset that caused them.
Enabling HTTP Strict Transport Security (HSTS)
This article provides steps for configuring HSTS in Cascade CMS.
Enabling or Disabling TLS Versions
This article contains steps for enabling or disabling certain versions of TLS.
Error constructing implementation
How to resolve the SSL/TLS "Error constructing implementation" error by checking Cascade CMS's key store configuration.
Error executing SQL DELETE FROM `cxml_history_item`
The following error message may appear when upgrading to Cascade 8 against a version of MySQL 5.7 prior to release 5.7.11: Migration failed for change set com/hannonhill/cascade/model/database/updater/updates/8_0/8_0_006.xml::8_0_006::artur.tomusiak: Reason: liquibase.exception.JDBCException: Error
Exception invoking method 'getAvailableIDs' in class sun.util.calendar.ZoneInfo
This particular error message is indicative of a missing startup parameter for the application.
External Link Checking Preferences
External Link Checking preferences allow administrators to configure system-wide external link checking behavior and functionality.
Firewall Considerations
This article contains information on inbound and outbound ports that the application will use.
Forcing connections to use SSL/TLS
Once the SSL/TLS connector has been enabled per these instructions, users may still be able to access the application through the default port 8080.
Generate a HAR file
Steps for capturing a HAR file of network activity for a support investigation, and how to redact it before sharing.
Generating a thread dump
How to capture a Java thread dump from Cascade CMS on Linux with kill -3, or on Windows with jcmd.
Google Analytics Connector
Set up the Google Analytics Connector so traffic figures from a Google Analytics 4 property appear on Sites, pages, files, and folders in Cascade CMS.
Granting Access to Specific Folders for Users/Groups
A worked example of hiding every Folder in a Site by default, then granting one Group access to just the Folder it needs.
Groups
A group is made up of one or more users with common permissions.
Header message of length [] received but the packetSize is only []
The AJP request header exceeds Tomcat's configured packetSize. Add a packetSize attribute to the connector in server.xml to resolve it.
How can I check what a User can do in a specific Site?
Use the Effective Abilities tool for a list of a user's abilities in a Site, or Assume Identity to see the system as they see it.
How can I enable request logging for Cascade CMS?
Add an AccessLogValve to tomcat/conf/context.xml to write a request log alongside the other Tomcat logs.
How can I find the O/S account running Cascade CMS?
The User Name field in Logs and System Information shows the account the application runs under.
How can I find which Java installation my Cascade CMS instance is using?
Check the JRE_HOME variable in the boot script for your platform, or read the JVM details from Logs and System Information.
How can I view the largest binary files within my database?
SQL queries for SQL Server, Oracle, and MySQL that list stored files from largest to smallest.
How do I change the name or URL of my site?
Update the Name and URL fields on the Properties tab of Site Settings.
How do I control User access to Folders and assets?
Set Access rights on an asset, and use Access for Contents to apply them down a Folder — merging rather than overwriting.
How do I delete a site?
Select the site in the Sites list and click Delete. Deleted sites cannot be restored.
How do I enable DEBUG logging?
Add a logging category or class at DEBUG level from the Logging Configuration tool, and reset it once you've collected what you need.
How do I give a User or Group access to a Site?
Assign a Site Role on the Roles tab of Site Settings, and make sure the user has Read access to the Site's Base Folder.
How do I rebuild my search indexes?
Trigger a search index rebuild from Administration > Search Indexing, and what to expect in the log and the Background Tasks Report while it runs.
Installation and Upgrades
Installing, upgrading, and moving a self-hosted Cascade CMS instance — installers per platform, the database, server configuration, and migration.
Installation/Upgrade (macOS)
Install or upgrade a self-hosted Cascade CMS instance on macOS using the graphical installer.
Installation/Upgrade (Windows)
Install or upgrade a self-hosted Cascade CMS instance on Windows, including the Windows service and command-line options.
Installation/Upgrade (ZIP)
Install or upgrade a self-hosted Cascade CMS instance from the ZIP distribution on Linux, macOS, or Windows.
Invalid XML character was found in the element content of the document
An "invalid XML character" error on submit means a control character was pasted into a WYSIWYG field. Here is how to find and remove it.
Invalid XML: The prefix "o" for element "o:p" is not bound
If you receive this error when trying to create or submit changes to an asset, there may be <o:p> tags in the source code of your editor that will need to be removed or converted to regular <p> tags before the asset can be submitted.
LDAP/Active Directory Authentication
Authenticating users against an existing LDAP or Active Directory server: connection options, policies, orphaned users, and the XML that configures it.
Load Balancing
Run Cascade CMS behind a load balancer: Tomcat and Apache configuration, cache synchronization, and what to check when sessions misbehave.
Logging Configuration
This section of the Administration area provides system administrators with the ability to configure additional logging for troubleshooting purposes.
Login Failed
This article describes steps that Administrators can take to troubleshoot failed login attempts for their users.
Logs and System Information
Download application log files and check the environment Cascade CMS is running in — memory, JVM settings, operating system, and version.
Migrating Cascade CMS to a new server
Move a self-hosted Cascade CMS instance to a new server: what to copy, what to reconfigure, and what to verify.
Migration Tool
Use the Universal Migration Tool to bring content from an existing site into Cascade CMS, mapping folders, Content Types, and fields.
Modifying Application Ports
This article outlines steps for changing the default port settings for the application.
Modifying the Database Configuration
This article contains steps to configure the database connection settings for the application
Modifying the Heap Size
This article contains the steps needed to modify the minimum (Xms) and maximum (Xmx) heap size for the application.
Modifying the Thread Stack Size
This article contains steps for configuring the Thread Stack Size for the application.
Monsido Integration
Pair a Monsido account with Cascade CMS and the Monsido Chrome extension so Monsido findings appear over the CMS interface.
MySQL 8: Public Key Retrieval is not allowed
Resolve the Public Key Retrieval error after upgrading to MySQL 8 in Cascade CMS.
MySQL: Can't create table
When starting Cascade CMS for the first time or after importing a new MySQL database, administrators may see an error message in the log file similar to the following: ERROR [StartupTasks] : *** Startup task: DatabaseIndexAndKeyManagerfailed to execute successfully: java.sql.SQLException: Can't crea
MySQL: Can't create/write to file
Organizations using MySQL may see an error message similar to the following when attempting to login to the system: Login failed: An error occurred: Startup task: DatabaseIndexAndKeyManager failed to execute successfully: java.sql.SQLException: Can't create/writeto file 'C:\WINNT\TEMP\#sql_718_0.MYI
Optimize Database
The Optimize Database tool removes and/or repairs various records within the database. It is NOT recommended to run this tool frequently.
ORA-22275: invalid LOB locator specified
Oracle users may encounter this error when attempting to copy, edit, or submit assets in the system.
Packet for query is too large
Resolve the MySQL max_allowed_packet error when uploading files into Cascade CMS.
PageRenderException: Could not transform with Script format
When previewing a page, you may see a full-page error of the type Could not transform with Script format...
Parameters missing
This article describes steps to take when you receive a 'Parameters missing' error while attempting to submit a file or page.
Permissions
The two spheres of permissions in Cascade CMS: system-wide abilities granted by a Role, and Site-level access to what a user can see and do.
Permissions in Cascade CMS: Sites, Roles, Groups, and Folder Access
Understand how site access, roles, groups, and folder-level permissions work together in Cascade CMS, with a practical decision matrix and troubleshooting guide.
Role Abilities
Every ability a System Role or Site Role can grant, grouped by the area of Cascade CMS it applies to.
Roles
A role is a set of a abilities that govern a user's access to a number of different areas in Cascade CMS.
Running Cascade CMS as a Linux service
This article contains samples using systemd and init.d service files.
Search and Indexing
Keeping Cascade CMS search working — rebuilding indexes, diagnosing missing results, granting access to Full Search, and the error messages the indexer produces.
Search failed: no segments file found
The "Search failed: no segments file found" error is resolved by rebuilding the Cascade CMS search indexes.
Search isn't returning expected results
Work through the Build Search Index task in the Background Tasks Report — its Status and Duration tell you whether the index built, stalled, or hit a permissions problem.
Secure LDAP sync fails after upgrade to Cascade CMS v8.11
Cascade CMS v8.11 comes bundled with a newer version of Java (JRE 8u191).
Securing session cookies
Mark the Cascade CMS session cookie secure and HttpOnly so it is only sent over TLS and is not readable from scripts.
Security Advisories
Hannon Hill's assessments of published CVEs and other security issues as they relate to Cascade CMS, including whether Cascade Cloud and on-premise installations are affected.
Setting up a test environment
Stand up a test copy of a Cascade CMS instance without letting it publish, email, or talk to connected services.
Setting up the database (MySQL)
Set up the Cascade CMS database on MySQL: install the server, adjust its configuration, and import the supplied database.
Setting up the database (Oracle)
Set up the Cascade CMS database on Oracle: create a tablespace and import the supplied database.
Setting up the database (SQL Server)
Set up the Cascade CMS database on SQL Server: attach the supplied database and set its isolation level to snapshot.
Site Import and Export
Cascade CMS supports the transfer of content and administrative properties from one Cascade CMS environment to another by way of exporting and importing Sites.
Siteimprove Integration
Cascade CMS's Siteimprove plugin allows existing Siteimprove customers to access data from the Siteimprove Intelligence Platform from within the CMS.
Sites
Sites are containers for organizing all content and administrative assets and properties for a website in Cascade CMS.
Snippets
With Snippets, your team can quickly create, update, and reuse standardized content elements throughout your site without any technical expertise.
Sorry, workflow is required to be able to continue but no workflows are available to you.
This error means that the user's Site Role doesn't allow them to Bypass workflow, but there isn't an applicable workflow available for the type of action they're taking.
SSL/TLS Configuration
Configuring SSL/TLS for the application requires two steps (as described in the official Tomcat documentation): Creating/preparing the Java keystore.
System Configuration
Configuring the application server behind a self-hosted Cascade CMS instance: memory and ports, TLS, logging, proxying, load balancing, and the license key.
System Dictionary
Add words to the system dictionary so the spell checker stops flagging them, export the dictionary, and copy a legacy user dictionary.
System Preferences
System preferences allow administrators to configure system-wide properties such as email, link checking, and content settings.
Table headers are poorly structured
How to clear the "Table headers are poorly structured" accessibility error by setting the correct cell type and scope on a table's header cells.
The driver could not establish a secure connection to SQL Server by using Secure Sockets Layer (SSL) encryption
When attempting to start Cascade CMS, organizations using SQL Server may be presented with the following error in the log files (which prevents the application from starting): ("encrypt" property is set to "true" and "trustServerCertificate" property is set to "false" but the driver could not establ
The driver could not establish a secure connection to SQL Server by using Secure Sockets Layer (SSL) encryption. Error: "Unexpected rethrowing"
This particular error message can appear on startup.
The index block with path {path} renders too much data
This message is displayed when an Index Block in the system renders a large amount of data and reaches the limit configured in the system Preferences.
Updating the license key
This article contains information on updating the license key.
Upgrading Tomcat independently of Cascade CMS
This article describes the steps needed in order to upgrade the bundled Tomcat installation
Users
Add users, apply password policies, check the abilities a user effectively has, and assume a user's identity to see what they see.
Using Apache 2.4 to proxy Cascade CMS
This article is provided as an example of using Apache 2.4 to to proxy Cascade CMS.
Web Governance
Web governance Connectors surface accessibility, broken link, spelling, and SEO findings from a third-party platform inside Cascade CMS.
Where can I find the Cascade CMS log files?
Log files are available from Logs and System Information in the Administration area, or in the tomcat/logs directory on the server.
Why can't my user upload images in the WYSIWYG or file chooser?
The Upload tab requires the Upload images in file chooser Site Role ability, and on versions before 8.22 also Bypass workflow.
Why can't my users access the full search feature?
Full Search and Replace lives in the Administration area, so users need a System Role with Access Administration Area enabled.
Why can't my users see anything in the Add Content menu?
An Asset Factory appears in Add Content only when the user's Group is listed in Applicable Groups on both the Asset Factory and its Container.
WordPress Connector
Set up a WordPress Connector so pages managed in Cascade CMS publish into a WordPress site.
Your roles do not allow you to advance workflow
This error indicates that the user's Site Role doesn't allow them to assign a Workflow to themselves or approve steps in a Workflow.