summaryrefslogtreecommitdiff
path: root/src/mongo/db/commands/authentication_commands.cpp
diff options
context:
space:
mode:
authorLucas de Castro Borges <lucas@gnuabordo.com.br>2025-02-11 15:07:35 -0300
committerLucas de Castro Borges <lucas@gnuabordo.com.br>2025-02-11 15:07:35 -0300
commit4cb8841196d0625dfa3825aa326f071cd27c7b8b (patch)
tree1682a647d4463397c119183369ae6f750d5fdcff /src/mongo/db/commands/authentication_commands.cpp
parentaa03c6362cbaa767638e6eed9b031d86dd2643d1 (diff)
parent8f0827553e09872941945a093b647a4211a9db7f (diff)
Update upstream source from tag 'upstream/6.0.0'master
Update to upstream version '6.0.0' with Debian dir 5604a80ec1c96ca76f25f40d78e6ef855abec322
Diffstat (limited to 'src/mongo/db/commands/authentication_commands.cpp')
-rw-r--r--src/mongo/db/commands/authentication_commands.cpp10
1 files changed, 7 insertions, 3 deletions
diff --git a/src/mongo/db/commands/authentication_commands.cpp b/src/mongo/db/commands/authentication_commands.cpp
index 81a844dacba..0fef67553d0 100644
--- a/src/mongo/db/commands/authentication_commands.cpp
+++ b/src/mongo/db/commands/authentication_commands.cpp
@@ -240,7 +240,7 @@ void _authenticateX509(OperationContext* opCtx, AuthenticationSession* session)
auto user = [&] {
if (session->getUserName().empty()) {
auto user = UserName(clientName.toString(), session->getDatabase().toString());
- session->updateUserName(user, true /* isMechX509 */);
+ session->updateUserName(user);
return user;
} else {
uassert(ErrorCodes::AuthenticationFailed,
@@ -258,6 +258,10 @@ void _authenticateX509(OperationContext* opCtx, AuthenticationSession* session)
auto sslConfiguration = opCtx->getClient()->session()->getSSLConfiguration();
+ uassert(ErrorCodes::AuthenticationFailed,
+ "Unable to verify x.509 certificate, as no CA has been provided.",
+ sslConfiguration->hasCA);
+
uassert(ErrorCodes::ProtocolError,
"X.509 authentication must always use the $external database.",
user.getDB() == kExternalDB);
@@ -337,9 +341,9 @@ AuthenticateReply authCommand(OperationContext* opCtx,
// Allows authenticating as the internal user against the admin database. This is to
// support the auth passthrough test framework on mongos (since you can't use the local
// database on a mongos, so you can't auth as the internal user without this).
- session->updateUserName(internalSecurityUser, mechanism == auth::kMechanismMongoX509);
+ session->updateUserName(internalSecurityUser);
} else {
- session->updateUserName(UserName{user, dbname}, mechanism == auth::kMechanismMongoX509);
+ session->updateUserName(UserName{user, dbname});
}
if (mechanism.empty()) {