[SERVER-59773] Use GMAC on the Audit Encryption Log Header Created: 03/Sep/21  Updated: 29/Oct/23  Resolved: 14/Oct/21

Status: Closed
Project: Core Server
Component/s: None
Affects Version/s: None
Fix Version/s: 5.1.0-rc0

Type: Task Priority: Major - P3
Reporter: Shreyas Kalyan Assignee: Erwin Pe
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Backwards Compatibility: Fully Compatible
Sprint: Security 2021-09-20, Security 2021-10-04, Security 2021-10-18
Participants:

 Description   

In order to ensure integrity for the audit log header, we need to use GCM with no plaintext input on the header - specifically the version and the timestamp. Details of the exact format are in the design document for this project.



 Comments   
Comment by Githook User [ 14/Oct/21 ]

Author:

{'name': 'Erwin Pe', 'email': 'erwin.pe@mongodb.com', 'username': 'erwee'}

Message: SERVER-59773 Generate/Verify MAC signature in audit encryption header
Branch: master
https://github.com/10gen/mongo-enterprise-modules/commit/ab2601ecb624fcf4056b3e033605a22b8b05edf2

Generated at Thu Feb 08 05:48:05 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.