influxdata/influxdb · error · Error

rustls error

Error message

rustls error: {0}

What it means

This variant wraps rustls::Error raised by the rustls TLS library during TLS operations, converted via #[from]. It indicates that while configuration may have been assembled, the TLS library itself rejected something during protocol operation — such as processing a peer's handshake, handling alerts, or internal rustls state violations. The rustls message follows 'rustls error: '.

Solutions

  1. Read the inner rustls message to determine whether it is a peer, certificate, or protocol issue
  2. Verify the certificate chain is complete (include intermediates) and the key matches
  3. Align client TLS version and cipher configuration with what the server supports
  4. Ensure clients use HTTPS against the TLS port and not plaintext HTTP
  5. Test with `openssl s_client -connect host:port` to reproduce the handshake failure independently

Example fix

// before: client forcing obsolete TLS version
--tls-min-version tls10
// after: use supported protocol versions
let versions = &[SupportedProtocolVersion::TLS_1_2, SupportedProtocolVersion::TLS_1_3];
Defensive patterns

Strategy: try-catch

Validate before calling

use tokio_rustls::rustls::pki_types::{CertificateDer, PrivateKeyDer, pem::PemObject};
fn load_and_check(cert_path: &str, key_path: &str) -> Result<(), String> {
    let cert = CertificateDer::from_pem_file(cert_path).map_err(|e| e.to_string())?;
    let key = PrivateKeyDer::from_pem_file(key_path).map_err(|e| e.to_string())?;
    let _ = tokio_rustls::rustls::ServerConfig::builder()
        .with_no_client_auth()
        .with_single_cert(vec![cert], key)
        .map_err(|e| e.to_string())?;
    Ok(())
}

Type guard

fn is_rustls_error(e: &influxdb3_server::Error) -> Option<&rustls::Error> {
    match e { influxdb3_server::Error::Rustls(r) => Some(r), _ => None }
}

Try / catch

match server_result {
    Err(influxdb3_server::Error::Rustls(r)) => {
        eprintln!("tls handshake/protocol failure: {r}");
        // do not retry blindly; inspect peer TLS setup first
    }
    Err(e) => eprintln!("server error: {e}"),
    Ok(v) => handle(v),
}

Prevention

When it happens

Trigger: A TLS handshake failing at the rustls level when a client connects over HTTPS; malformed or unsupported TLS records from a peer; certificate validation issues surfaced at handshake time; rustls API misuse detected at runtime.

Common situations: Clients connecting with unsupported TLS versions or cipher suites; corrupted or mismatched certificate chains; clients speaking plaintext HTTP to a TLS-only port (or vice versa); intermediaries/proxies mangling TLS records.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/fe62fcd98fdf6281. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_server/src/lib.rs:87

    #[error("database not found {db_name}")]
    DatabaseNotFound { db_name: String },

    #[error("datafusion error: {0}")]
    DataFusion(#[from] datafusion::error::DataFusionError),

    #[error("influxdb3_write error: {0}")]
    InfluxDB3Write(#[from] influxdb3_write::Error),

    #[error("from hex error: {0}")]
    FromHex(#[from] hex::FromHexError),

    #[error("io error: {0}")]
    Io(#[from] std::io::Error),

    #[error("tls config error: {0}")]
    TlsConfig(String),

    #[error("rustls error: {0}")]
    Rustls(#[from] rustls::Error),
}

pub type Result<T, E = Error> = std::result::Result<T, E>;

#[derive(Debug, Clone)]
pub struct CommonServerState {
    catalog: Arc<Catalog>,
    metrics: Arc<metric::Registry>,
    trace_exporter: Option<Arc<trace_exporters::export::AsyncExporter>>,
    trace_header_parser: TraceHeaderParser,
    telemetry_store: Arc<TelemetryStore>,
}

impl CommonServerState {
    pub fn new(
        catalog: Arc<Catalog>,
        metrics: Arc<metric::Registry>,

View on GitHub (pinned to 06200ef96b)