{"record":{"id":"fe62fcd98fdf6281","repo":"influxdata/influxdb","slug":"rustls-error-0","errorCode":null,"errorMessage":"rustls error: {0}","messagePattern":"rustls error: (.+?)","errorType":"error_code","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"influxdb3_server/src/lib.rs","lineNumber":87,"sourceCode":"    #[error(\"database not found {db_name}\")]\n    DatabaseNotFound { db_name: String },\n\n    #[error(\"datafusion error: {0}\")]\n    DataFusion(#[from] datafusion::error::DataFusionError),\n\n    #[error(\"influxdb3_write error: {0}\")]\n    InfluxDB3Write(#[from] influxdb3_write::Error),\n\n    #[error(\"from hex error: {0}\")]\n    FromHex(#[from] hex::FromHexError),\n\n    #[error(\"io error: {0}\")]\n    Io(#[from] std::io::Error),\n\n    #[error(\"tls config error: {0}\")]\n    TlsConfig(String),\n\n    #[error(\"rustls error: {0}\")]\n    Rustls(#[from] rustls::Error),\n}\n\npub type Result<T, E = Error> = std::result::Result<T, E>;\n\n#[derive(Debug, Clone)]\npub struct CommonServerState {\n    catalog: Arc<Catalog>,\n    metrics: Arc<metric::Registry>,\n    trace_exporter: Option<Arc<trace_exporters::export::AsyncExporter>>,\n    trace_header_parser: TraceHeaderParser,\n    telemetry_store: Arc<TelemetryStore>,\n}\n\nimpl CommonServerState {\n    pub fn new(\n        catalog: Arc<Catalog>,\n        metrics: Arc<metric::Registry>,","sourceCodeStart":69,"sourceCodeEnd":105,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_server/src/lib.rs#L69-L105","documentation":"This variant wraps rustls::Error raised by the rustls TLS library during TLS operations, converted via #[from]. It indicates that while configuration may have been assembled, the TLS library itself rejected something during protocol operation — such as processing a peer's handshake, handling alerts, or internal rustls state violations. The rustls message follows 'rustls error: '.","triggerScenarios":"A TLS handshake failing at the rustls level when a client connects over HTTPS; malformed or unsupported TLS records from a peer; certificate validation issues surfaced at handshake time; rustls API misuse detected at runtime.","commonSituations":"Clients connecting with unsupported TLS versions or cipher suites; corrupted or mismatched certificate chains; clients speaking plaintext HTTP to a TLS-only port (or vice versa); intermediaries/proxies mangling TLS records.","solutions":["Read the inner rustls message to determine whether it is a peer, certificate, or protocol issue","Verify the certificate chain is complete (include intermediates) and the key matches","Align client TLS version and cipher configuration with what the server supports","Ensure clients use HTTPS against the TLS port and not plaintext HTTP","Test with `openssl s_client -connect host:port` to reproduce the handshake failure independently"],"exampleFix":"// before: client forcing obsolete TLS version\n--tls-min-version tls10\n// after: use supported protocol versions\nlet versions = &[SupportedProtocolVersion::TLS_1_2, SupportedProtocolVersion::TLS_1_3];","handlingStrategy":"try-catch","validationCode":"use tokio_rustls::rustls::pki_types::{CertificateDer, PrivateKeyDer, pem::PemObject};\nfn load_and_check(cert_path: &str, key_path: &str) -> Result<(), String> {\n    let cert = CertificateDer::from_pem_file(cert_path).map_err(|e| e.to_string())?;\n    let key = PrivateKeyDer::from_pem_file(key_path).map_err(|e| e.to_string())?;\n    let _ = tokio_rustls::rustls::ServerConfig::builder()\n        .with_no_client_auth()\n        .with_single_cert(vec![cert], key)\n        .map_err(|e| e.to_string())?;\n    Ok(())\n}","typeGuard":"fn is_rustls_error(e: &influxdb3_server::Error) -> Option<&rustls::Error> {\n    match e { influxdb3_server::Error::Rustls(r) => Some(r), _ => None }\n}","tryCatchPattern":"match server_result {\n    Err(influxdb3_server::Error::Rustls(r)) => {\n        eprintln!(\"tls handshake/protocol failure: {r}\");\n        // do not retry blindly; inspect peer TLS setup first\n    }\n    Err(e) => eprintln!(\"server error: {e}\"),\n    Ok(v) => handle(v),\n}","preventionTips":["Include the full certificate chain (leaf + intermediates) in the cert file","Restrict server to TLS 1.2/1.3 and align client versions","Test connectivity with openssl s_client before production rollout","Do not mix plaintext HTTP clients with TLS-only ports; handle non-TLS connections on a separate listener"],"tags":["influxdb3","tls","rustls","handshake"],"backgroundTag":"tls-handshake-failure","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}