summaryrefslogtreecommitdiff
path: root/src/mongo/util/net
diff options
context:
space:
mode:
authorVarun Ravichandran <varun.ravichandran@mongodb.com>2021-07-19 19:06:08 +0000
committerEvergreen Agent <no-reply@evergreen.mongodb.com>2021-08-17 16:18:10 +0000
commit9f329ae9bb1c2f3e9e4eb0b0114c3eb6a3627d52 (patch)
treec20efe39c0f5a8e380869c8436e2656f2d208214 /src/mongo/util/net
parent3050d450c5b1ee04825eedcaf44053cfe48d9100 (diff)
downloadmongo-9f329ae9bb1c2f3e9e4eb0b0114c3eb6a3627d52.tar.gz
SERVER-57004: Move FIPSMode flag to enterprise
Diffstat (limited to 'src/mongo/util/net')
-rw-r--r--src/mongo/util/net/ssl_options_client.idl9
-rw-r--r--src/mongo/util/net/ssl_options_server.idl7
-rw-r--r--src/mongo/util/net/ssl_options_test.cpp4
3 files changed, 0 insertions, 20 deletions
diff --git a/src/mongo/util/net/ssl_options_client.idl b/src/mongo/util/net/ssl_options_client.idl
index 52884b0d028..1c40af194b4 100644
--- a/src/mongo/util/net/ssl_options_client.idl
+++ b/src/mongo/util/net/ssl_options_client.idl
@@ -98,15 +98,6 @@ configs:
cpp_varname: "sslGlobalParams.sslAllowInvalidCertificates"
requires: tls
- "tls.FIPSMode":
- description: "Activate FIPS 140-2 mode at startup"
- short_name: tlsFIPSMode
- deprecated_name: "ssl.FIPSMode"
- deprecated_short_name: sslFIPSMode
- arg_vartype: Switch
- cpp_varname: "sslGlobalParams.sslFIPSMode"
- requires: tls
-
"tls.certificateSelector":
description: "TLS Certificate in system store"
short_name: tlsCertificateSelector
diff --git a/src/mongo/util/net/ssl_options_server.idl b/src/mongo/util/net/ssl_options_server.idl
index 64d7b10aaf0..58b05893a36 100644
--- a/src/mongo/util/net/ssl_options_server.idl
+++ b/src/mongo/util/net/ssl_options_server.idl
@@ -154,13 +154,6 @@ configs:
deprecated_short_name: sslAllowInvalidCertificates
arg_vartype: Switch
cpp_varname: sslGlobalParams.sslAllowInvalidCertificates
- "net.tls.FIPSMode":
- description: "Activate FIPS 140-2 mode at startup"
- short_name: tlsFIPSMode
- deprecated_name: "net.ssl.FIPSMode"
- deprecated_short_name: sslFIPSMode
- arg_vartype: Switch
- cpp_varname: sslGlobalParams.sslFIPSMode
# Certificate Selectors are only available on OSX/Windows with --ssl-provider=native (or auto)
"net.tls.certificateSelector":
diff --git a/src/mongo/util/net/ssl_options_test.cpp b/src/mongo/util/net/ssl_options_test.cpp
index c666d9636c2..ec66f5ba7ae 100644
--- a/src/mongo/util/net/ssl_options_test.cpp
+++ b/src/mongo/util/net/ssl_options_test.cpp
@@ -211,7 +211,6 @@ TEST(SetupOptions, tlsModeRequired) {
argv.push_back("--tlsAllowInvalidHostnames");
argv.push_back("--tlsAllowInvalidCertificates");
argv.push_back("--tlsWeakCertificateValidation");
- argv.push_back("--tlsFIPSMode");
argv.push_back("--tlsCertificateKeyFilePassword");
argv.push_back("pw1");
argv.push_back("--tlsClusterPassword");
@@ -241,7 +240,6 @@ TEST(SetupOptions, tlsModeRequired) {
ASSERT_EQ(::mongo::sslGlobalParams.sslAllowInvalidHostnames, true);
ASSERT_EQ(::mongo::sslGlobalParams.sslAllowInvalidCertificates, true);
ASSERT_EQ(::mongo::sslGlobalParams.sslWeakCertificateValidation, true);
- ASSERT_EQ(::mongo::sslGlobalParams.sslFIPSMode, true);
ASSERT_EQ(::mongo::sslGlobalParams.sslPEMKeyPassword, "pw1");
ASSERT_EQ(::mongo::sslGlobalParams.sslClusterPassword, "pw2");
ASSERT_EQ(static_cast<int>(::mongo::sslGlobalParams.sslDisabledProtocols.back()),
@@ -277,7 +275,6 @@ TEST(SetupOptions, sslModeRequired) {
argv.push_back("--sslAllowInvalidHostnames");
argv.push_back("--sslAllowInvalidCertificates");
argv.push_back("--sslWeakCertificateValidation");
- argv.push_back("--sslFIPSMode");
argv.push_back("--sslPEMKeyPassword");
argv.push_back("pw1");
argv.push_back("--sslClusterPassword");
@@ -307,7 +304,6 @@ TEST(SetupOptions, sslModeRequired) {
ASSERT_EQ(::mongo::sslGlobalParams.sslAllowInvalidHostnames, true);
ASSERT_EQ(::mongo::sslGlobalParams.sslAllowInvalidCertificates, true);
ASSERT_EQ(::mongo::sslGlobalParams.sslWeakCertificateValidation, true);
- ASSERT_EQ(::mongo::sslGlobalParams.sslFIPSMode, true);
ASSERT_EQ(::mongo::sslGlobalParams.sslPEMKeyPassword, "pw1");
ASSERT_EQ(::mongo::sslGlobalParams.sslClusterPassword, "pw2");
ASSERT_EQ(static_cast<int>(::mongo::sslGlobalParams.sslDisabledProtocols.back()),