Include TLS SNI extensions advertised by clients in debug logs

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Fixed
    • Priority: Major - P3
    • 4.7.0
    • Affects Version/s: None
    • Component/s: Logging, Security
    • None
    • Fully Compatible
    • Security 2020-08-10
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      The TLS SNI extension is advertised by clients, to indicate the server name they believe they are connecting to. Servers are expected to use this information to, for example, select an X.509 certificate with a Subject Alternative Name which it would expect the client to accept. MongoDB uses this information to tweak the topology information advertised in isMaster.

      It would be useful for debugging to include a client's SNI extension in the debug logs.

            Assignee:
            Gabriel Marks
            Reporter:
            Spencer Jackson
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: