diff options
author | Varun Ravichandran <varun.ravichandran@mongodb.com> | 2021-07-19 19:06:08 +0000 |
---|---|---|
committer | Evergreen Agent <no-reply@evergreen.mongodb.com> | 2021-08-17 16:18:10 +0000 |
commit | 9f329ae9bb1c2f3e9e4eb0b0114c3eb6a3627d52 (patch) | |
tree | c20efe39c0f5a8e380869c8436e2656f2d208214 /src/mongo/util/net | |
parent | 3050d450c5b1ee04825eedcaf44053cfe48d9100 (diff) | |
download | mongo-9f329ae9bb1c2f3e9e4eb0b0114c3eb6a3627d52.tar.gz |
SERVER-57004: Move FIPSMode flag to enterprise
Diffstat (limited to 'src/mongo/util/net')
-rw-r--r-- | src/mongo/util/net/ssl_options_client.idl | 9 | ||||
-rw-r--r-- | src/mongo/util/net/ssl_options_server.idl | 7 | ||||
-rw-r--r-- | src/mongo/util/net/ssl_options_test.cpp | 4 |
3 files changed, 0 insertions, 20 deletions
diff --git a/src/mongo/util/net/ssl_options_client.idl b/src/mongo/util/net/ssl_options_client.idl index 52884b0d028..1c40af194b4 100644 --- a/src/mongo/util/net/ssl_options_client.idl +++ b/src/mongo/util/net/ssl_options_client.idl @@ -98,15 +98,6 @@ configs: cpp_varname: "sslGlobalParams.sslAllowInvalidCertificates" requires: tls - "tls.FIPSMode": - description: "Activate FIPS 140-2 mode at startup" - short_name: tlsFIPSMode - deprecated_name: "ssl.FIPSMode" - deprecated_short_name: sslFIPSMode - arg_vartype: Switch - cpp_varname: "sslGlobalParams.sslFIPSMode" - requires: tls - "tls.certificateSelector": description: "TLS Certificate in system store" short_name: tlsCertificateSelector diff --git a/src/mongo/util/net/ssl_options_server.idl b/src/mongo/util/net/ssl_options_server.idl index 64d7b10aaf0..58b05893a36 100644 --- a/src/mongo/util/net/ssl_options_server.idl +++ b/src/mongo/util/net/ssl_options_server.idl @@ -154,13 +154,6 @@ configs: deprecated_short_name: sslAllowInvalidCertificates arg_vartype: Switch cpp_varname: sslGlobalParams.sslAllowInvalidCertificates - "net.tls.FIPSMode": - description: "Activate FIPS 140-2 mode at startup" - short_name: tlsFIPSMode - deprecated_name: "net.ssl.FIPSMode" - deprecated_short_name: sslFIPSMode - arg_vartype: Switch - cpp_varname: sslGlobalParams.sslFIPSMode # Certificate Selectors are only available on OSX/Windows with --ssl-provider=native (or auto) "net.tls.certificateSelector": diff --git a/src/mongo/util/net/ssl_options_test.cpp b/src/mongo/util/net/ssl_options_test.cpp index c666d9636c2..ec66f5ba7ae 100644 --- a/src/mongo/util/net/ssl_options_test.cpp +++ b/src/mongo/util/net/ssl_options_test.cpp @@ -211,7 +211,6 @@ TEST(SetupOptions, tlsModeRequired) { argv.push_back("--tlsAllowInvalidHostnames"); argv.push_back("--tlsAllowInvalidCertificates"); argv.push_back("--tlsWeakCertificateValidation"); - argv.push_back("--tlsFIPSMode"); argv.push_back("--tlsCertificateKeyFilePassword"); argv.push_back("pw1"); argv.push_back("--tlsClusterPassword"); @@ -241,7 +240,6 @@ TEST(SetupOptions, tlsModeRequired) { ASSERT_EQ(::mongo::sslGlobalParams.sslAllowInvalidHostnames, true); ASSERT_EQ(::mongo::sslGlobalParams.sslAllowInvalidCertificates, true); ASSERT_EQ(::mongo::sslGlobalParams.sslWeakCertificateValidation, true); - ASSERT_EQ(::mongo::sslGlobalParams.sslFIPSMode, true); ASSERT_EQ(::mongo::sslGlobalParams.sslPEMKeyPassword, "pw1"); ASSERT_EQ(::mongo::sslGlobalParams.sslClusterPassword, "pw2"); ASSERT_EQ(static_cast<int>(::mongo::sslGlobalParams.sslDisabledProtocols.back()), @@ -277,7 +275,6 @@ TEST(SetupOptions, sslModeRequired) { argv.push_back("--sslAllowInvalidHostnames"); argv.push_back("--sslAllowInvalidCertificates"); argv.push_back("--sslWeakCertificateValidation"); - argv.push_back("--sslFIPSMode"); argv.push_back("--sslPEMKeyPassword"); argv.push_back("pw1"); argv.push_back("--sslClusterPassword"); @@ -307,7 +304,6 @@ TEST(SetupOptions, sslModeRequired) { ASSERT_EQ(::mongo::sslGlobalParams.sslAllowInvalidHostnames, true); ASSERT_EQ(::mongo::sslGlobalParams.sslAllowInvalidCertificates, true); ASSERT_EQ(::mongo::sslGlobalParams.sslWeakCertificateValidation, true); - ASSERT_EQ(::mongo::sslGlobalParams.sslFIPSMode, true); ASSERT_EQ(::mongo::sslGlobalParams.sslPEMKeyPassword, "pw1"); ASSERT_EQ(::mongo::sslGlobalParams.sslClusterPassword, "pw2"); ASSERT_EQ(static_cast<int>(::mongo::sslGlobalParams.sslDisabledProtocols.back()), |