Extend the proxy protocol to support TLS sessions

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Fixed
    • Priority: Major - P3
    • 8.3.0-rc0
    • Affects Version/s: None
    • Component/s: None
    • None
    • Server Security
    • Fully Compatible
    • Server Security 2026-02-13, Server Security 2026-02-27, Server Security 2026-03-13
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      We would like to support proxies which terminate TLS. However, we have features which depend on the Server terminating TLS sessions, and having access to endpoint metadata. Specifically, we will need SNI, MONGODB-X509, and X.509 authorization to work via the proxy protocol. We should extend the proxy protocol to forward this information.

      Note, this information is used authentication systems to make security decisions. We must continue to prevent the proxy protocol from being used by untrusted clients.

            Assignee:
            Chye Lin Chee
            Reporter:
            Spencer Jackson
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: