[SERVER-58591] Better instrumentation for TLS authentication problem during concurrent tenant migration Created: 15/Jul/21  Updated: 29/Oct/23  Resolved: 19/Jul/21

Status: Closed
Project: Core Server
Component/s: None
Affects Version/s: 5.0.0
Fix Version/s: 5.1.0-rc0

Type: Bug Priority: Major - P3
Reporter: Andrew Shuvalov (Inactive) Assignee: Andrew Shuvalov (Inactive)
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Related
is related to SERVER-69464 "Attempt to switch user during SASL a... Closed
Backwards Compatibility: Fully Compatible
Operating System: ALL
Steps To Reproduce:

Failure from BF-21501

 

Sprint: Core Eng TPM 2021-07-30
Participants:
Case:

 Description   

There is a race somewhere in TLS authentication during many concurrent tenant migrations. The recipient d20522 does not match the name coming with cert from the donor:

 

d20522| 2021-06-10T03:12:12.909+00:00 I  ACCESS   5286202 [conn16] "Different user name was supplied to saslSupportedMechs","attr":{"error":{"code":17,"codeName":"ProtocolError","errmsg":"Attempt to switch user during SASL authentication."}}

Need better logging in the chain, then will wait for it to happen again.



 Comments   
Comment by Vivian Ge (Inactive) [ 06/Oct/21 ]

Updating the fixversion since branching activities occurred yesterday. This ticket will be in rc0 when it’s been triggered. For more active release information, please keep an eye on #server-release. Thank you!

Comment by Githook User [ 16/Jul/21 ]

Author:

{'name': 'Andrew Shuvalov', 'email': 'andrew.shuvalov@mongodb.com', 'username': 'shuvalov-mdb'}

Message: SERVER-58591: Better instrumentation for TLS authentication problem during concurrent tenant migration
Branch: master
https://github.com/mongodb/mongo/commit/0b45999759258634fea8fe8b9c63a9591c4c654b

Generated at Thu Feb 08 05:44:56 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.