-
Type: Bug
-
Resolution: Fixed
-
Priority: Major - P3
-
Affects Version/s: 4.4.16
-
Component/s: None
-
None
-
Server Security
-
Fully Compatible
-
ALL
-
-
Security 2022-12-12, Security 2022-12-26, Security 2023-01-09, Security 2023-01-23
-
(copied to CRM)
-
141
When running with SCRAM-SHA-256 not enabled on a mongod server, speculative authentication attempts with SCRAM-SHA-256 cause audit messages to be logged indicating authentication failures (result code 18).
This is undesirable, as the appearance of an authentication failure message in the audit log can be taken as an indication that someone is actually trying to login with a bad password.
The ask here is to stop triggering audit events for speculative authentication failures.