-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Unknown
-
Affects Version/s: None
-
None
Context
The encryption commands (create-collection, status, rewrap) build a ClientEncryption through MongoDB\Laravel\Encryption\AutoEncryption::getClientEncryption(). That method forwards only three options to the driver:
return $this->connection()->getClient()->createClientEncryption([ 'keyVaultClient' => ..., 'keyVaultNamespace' => ..., 'kmsProviders' => ..., ]);
Every other option of the driver's AutoEncryptionOptionsShape is dropped, tlsOptions in particular.
Impact
tlsOptions carries the TLS settings of each KMS provider (tlsCAFile, tlsCertificateKeyFile, and so on). Without it, a KMS reachable only through a private CA cannot be used, because libmongocrypt always speaks HTTPS to a custom KMS endpoint and there is no other way to declare the CA.
This blocks using the commands against a local or self-hosted KMS (LocalStack, Vault, an internal KMS), and against any endpoint with a private certificate. It came up while testing the aws provider of the rewrap command against a local mock: the data key could only be created after patching this method.
Requested change
Forward the ClientEncryption options from the connection configuration, at least tlsOptions, and keep them aligned with the driver's AutoEncryptionOptionsShape (see [PHPLIB-1947|https://github.com/mongodb/mongo-php-library/pull/1991] for the reference shape).
Decide which options belong on ClientEncryption rather than on the auto-encryption manager: keyVaultClient, keyVaultNamespace, kmsProviders, tlsOptions, extraOptions.
Notes
- masterKey is already handled separately, when a data key is generated (createDataKey) and when it is rewrapped (rewrapManyDataKey).
- The auto-encryption manager receives the whole autoEncryption document through prepareDriverOptions(), so schemaMap, bypassAutoEncryption and bypassQueryAnalysis already reach it. Only the ClientEncryption path is incomplete.