[SERVER-42505] Periodically check if KMIP key is in the Active State Created: 30/Jul/19  Updated: 29/Oct/23  Resolved: 21/Jan/22

Status: Closed
Project: Core Server
Component/s: None
Affects Version/s: None
Fix Version/s: 5.3.0

Type: Task Priority: Major - P3
Reporter: Mark Benvenuto Assignee: Shreyas Kalyan
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Related
Backwards Compatibility: Major Change
Sprint: Security 2021-11-29, Security 2021-12-13, Security 2022-01-10, Security 2022-01-24
Participants:

 Description   

If a KMIP symmetric key is disabled on the server, the server will not know this until a restart of the server.

We should poll the KMIP server via Get Attributes and check if State == Active. If the state is not active, then we would shutdown the server.

The polling would need to be robust to KMIP server unavailability. The user may want to opt-out of this behavior.



 Comments   
Comment by Githook User [ 21/Jan/22 ]

Author:

{'name': 'Shreyas Kalyan', 'email': 'shreyas.kalyan@10gen.com', 'username': 'shreyaskalyan'}

Message: SERVER-42505 Periodically check if KMIP key is in the Active State
Branch: master
https://github.com/10gen/mongo-enterprise-modules/commit/2682cfaaeb7dc174cafd316edb101418f67af05c

Generated at Thu Feb 08 05:00:40 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.