ExportXMLWordPrintableJSON

    • Type: Bug
    • Resolution: Fixed
    • Priority: Unknown
    • 5.12.0
    • Affects Version/s: None
    • None
    • Not Needed
    • None
    • None
    • None
    • None
    • None
    • None

      Context

      The encryption commands (create-collection, status, rewrap) build a ClientEncryption through MongoDB\Laravel\Encryption\AutoEncryption::getClientEncryption(). That method forwards only three options to the driver:

      return $this->connection()->getClient()->createClientEncryption([
          'keyVaultClient' => ...,
          'keyVaultNamespace' => ...,
          'kmsProviders' => ...,
      ]);
      

      Every other option of the driver's AutoEncryptionOptionsShape is dropped, tlsOptions in particular.

      Impact

      tlsOptions carries the TLS settings of each KMS provider (tlsCAFile, tlsCertificateKeyFile, and so on). Without it, a KMS reachable only through a private CA cannot be used, because libmongocrypt always speaks HTTPS to a custom KMS endpoint and there is no other way to declare the CA.

      This blocks using the commands against a local or self-hosted KMS (LocalStack, Vault, an internal KMS), and against any endpoint with a private certificate. It came up while testing the aws provider of the rewrap command against a local mock: the data key could only be created after patching this method.

      Requested change

      Forward the ClientEncryption options from the connection configuration, at least tlsOptions, and keep them aligned with the driver's AutoEncryptionOptionsShape (see [PHPLIB-1947|https://github.com/mongodb/mongo-php-library/pull/1991] for the reference shape).

      Decide which options belong on ClientEncryption rather than on the auto-encryption manager: keyVaultClient, keyVaultNamespace, kmsProviders, tlsOptions, extraOptions.

      Notes

      • masterKey is already handled separately, when a data key is generated (createDataKey) and when it is rewrapped (rewrapManyDataKey).
      • The auto-encryption manager receives the whole autoEncryption document through prepareDriverOptions(), so schemaMap, bypassAutoEncryption and bypassQueryAnalysis already reach it. Only the ClientEncryption path is incomplete.

              Assignee:
              Jérôme Tamarelle
              Reporter:
              Jérôme Tamarelle
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: