Connecting to MongoDB 4.2.10 Enterprise Encrypted Installation on Windows 10

Suzette Cohen shared this problem 3 years ago
Not a Problem

Unable to connect to Encrypted MongoDB 4.2.10 Enterprise edition on Windows 10

I Choose X.509 under Authentification, I Have root CA file and Client Certificate.

On windows Certificate file is .pfx file, I am asked for .pem file. Also with .pem file it uses deprecated SSL instead of TLS (we use TLS 1.2)

Replies (1)

photo
1

I tried it already. Still getting MongoError: authFailed at Connection.messageHandler

(C:\\Users\\UserName\\AppData\\Local\\Programs\\nosqlbooster4mongo\\resources\\app.asar\node_modules\\mongodb\\

lib\\core.connection\\connection.js:359:18

at Connection.emit (events.js:2013:13).....

Very long error stack ending with:

at TLSWrap.onStreamRead(internal/stream_base_common.js:166:17)

I added carriage return at the end of each line to make it easier to read.

It should all be one long string from Error to: (events.js:203:13)

May be it's because it uses: "SSL":true and not TLS.

photo
1

It is not SSL problem. The Connection string uses TLS, contains: tls=true in the connection string.

photo
1

The connection problem is difficult to solve, there are many factors that affect the connection problem, and we have no way to debug and reproduce the error locally unless you can provide a test database account that can be accessed remotely.

And, have you ever successfully connected to a mongo compass or mongo shell?

If the connection is successful, can you compare the configuration of the connection with the actual connection URI of NoSQLBooster.

Please use "test connection" to diagnose the connection and click "Copy report to clipboard", and send the report to me (support@nosqlbooster.com).

213991bdd0f446a3aa393dadfbbd69db

photo
1

I tested the connection. I have create CA certificate and mongoDb certificate using: OpenSSL. When I Press the To URI it says: tls=true, tlsCertificateKeyFile=CertName.pem...

But after pressing "Test Connection" it tries to connect with: ssl=true and sslCert=...

and changes the URI to: SSL instead of TLS.

The result is: failed to connect to server [ServerName:27017] on first connect {MongoError: auth failed...

TLSWrap.onStreamRead(internal/stream_base_common.js:167:17) {\n oj=0, code:18, codeName: AuthentificationFailed name:'MongoError'

I hope it helps.

photo
1

P.S. I do connect to Mongo from Command line using the same certificate (I use its thumbprint instead of Certificate file name.

photo
1

Hi

It also works with the same CA file and Certificate file.

I enter the file path as: C:\Crt\CAfile.pem and: C:\Crt\ClientCert.pem

photo
1

For the mongo client, tls=true and ssl=true are equivalent, there is no difference, this is not a problem. Please refer to http://mongodb.github.io/node-mongodb-native/3.6/api/MongoClient.html

If you ever successfully connected to the mongo compass GUI or mongo shell, could you give me your MongoDB URI or command-line parameters?

And, could you please give the full test report? Use "test connection" to diagnose the connection and click "Copy report to clipboard". You can also send an email to support(support@nosqlbooster.com).

photo
1

Hi

I successfully connected to mongo shell using:

mongo --host server1020 --tls --tlsCertificateKeyFile C:\Crt\MongoCert.pem --tlsCertificateKeyFilePassword=Password --tlsCAFile C:\Crt\CaCert.pem.

NoSQLBooster Connection Result is:


Version: 6.2.9


OS:{"platform":"win32","type":"Windows_NT","release":"6.1.7601","mem":"16G"}


License: Commercial 211180


Brief:


Connect to server1020 Status:OK Duration:


Error:


MongoNetworkError: failed to connect to server[server1020:27017] on first connect

photo
1

From the command line argument you gave to mongo shell, the auth mode should not be x.509, but should be None or Basic. Please change your authentication mode and try it again.

b6fa0d9a1d8614f2f0ff7091d41da59d

photo
1

Thanks.

I can connect now successfully.

photo
Leave a Comment
 
Attach a file