Secure Channel fails TLS handshake due to hostname mismatch

XMLWordPrintableJSON

    • Type: Bug
    • Resolution: Unresolved
    • Priority: Minor - P4
    • None
    • Affects Version/s: None
    • Component/s: None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Observed on VS 2015 variants in patch builds (one, two).

      Given the C driver CA certificate being registered on the system and a mock KMS server running on port 7999, the TLS handshake as initiated by test_kms_tls_cert_valid() fails with the error SSL Certification verification failed: hostname doesn't match certificate when attempting to resolve "127.0.0.1:7999", but succeeds when "localhost:7999" is provided instead. This suggests there may be a bug in the Secure Channel library's implementation of hostname resolution in the version being used by the VS 2015 variant on Evergreen.

            Assignee:
            Unassigned
            Reporter:
            Ezra Chung
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: