diff options
Diffstat (limited to 'src/mongo/db/commands/authentication_commands.cpp')
| -rw-r--r-- | src/mongo/db/commands/authentication_commands.cpp | 10 |
1 files changed, 7 insertions, 3 deletions
diff --git a/src/mongo/db/commands/authentication_commands.cpp b/src/mongo/db/commands/authentication_commands.cpp index 81a844dacba..0fef67553d0 100644 --- a/src/mongo/db/commands/authentication_commands.cpp +++ b/src/mongo/db/commands/authentication_commands.cpp @@ -240,7 +240,7 @@ void _authenticateX509(OperationContext* opCtx, AuthenticationSession* session) auto user = [&] { if (session->getUserName().empty()) { auto user = UserName(clientName.toString(), session->getDatabase().toString()); - session->updateUserName(user, true /* isMechX509 */); + session->updateUserName(user); return user; } else { uassert(ErrorCodes::AuthenticationFailed, @@ -258,6 +258,10 @@ void _authenticateX509(OperationContext* opCtx, AuthenticationSession* session) auto sslConfiguration = opCtx->getClient()->session()->getSSLConfiguration(); + uassert(ErrorCodes::AuthenticationFailed, + "Unable to verify x.509 certificate, as no CA has been provided.", + sslConfiguration->hasCA); + uassert(ErrorCodes::ProtocolError, "X.509 authentication must always use the $external database.", user.getDB() == kExternalDB); @@ -337,9 +341,9 @@ AuthenticateReply authCommand(OperationContext* opCtx, // Allows authenticating as the internal user against the admin database. This is to // support the auth passthrough test framework on mongos (since you can't use the local // database on a mongos, so you can't auth as the internal user without this). - session->updateUserName(internalSecurityUser, mechanism == auth::kMechanismMongoX509); + session->updateUserName(internalSecurityUser); } else { - session->updateUserName(UserName{user, dbname}, mechanism == auth::kMechanismMongoX509); + session->updateUserName(UserName{user, dbname}); } if (mechanism.empty()) { |
