influxdata/influxdb · error · Error
rustls error
Error message
rustls error: {0} What it means
This variant wraps rustls::Error raised by the rustls TLS library during TLS operations, converted via #[from]. It indicates that while configuration may have been assembled, the TLS library itself rejected something during protocol operation — such as processing a peer's handshake, handling alerts, or internal rustls state violations. The rustls message follows 'rustls error: '.
Solutions
- Read the inner rustls message to determine whether it is a peer, certificate, or protocol issue
- Verify the certificate chain is complete (include intermediates) and the key matches
- Align client TLS version and cipher configuration with what the server supports
- Ensure clients use HTTPS against the TLS port and not plaintext HTTP
- Test with `openssl s_client -connect host:port` to reproduce the handshake failure independently
Example fix
// before: client forcing obsolete TLS version --tls-min-version tls10 // after: use supported protocol versions let versions = &[SupportedProtocolVersion::TLS_1_2, SupportedProtocolVersion::TLS_1_3];
Defensive patterns
Strategy: try-catch
Validate before calling
use tokio_rustls::rustls::pki_types::{CertificateDer, PrivateKeyDer, pem::PemObject};
fn load_and_check(cert_path: &str, key_path: &str) -> Result<(), String> {
let cert = CertificateDer::from_pem_file(cert_path).map_err(|e| e.to_string())?;
let key = PrivateKeyDer::from_pem_file(key_path).map_err(|e| e.to_string())?;
let _ = tokio_rustls::rustls::ServerConfig::builder()
.with_no_client_auth()
.with_single_cert(vec![cert], key)
.map_err(|e| e.to_string())?;
Ok(())
} Type guard
fn is_rustls_error(e: &influxdb3_server::Error) -> Option<&rustls::Error> {
match e { influxdb3_server::Error::Rustls(r) => Some(r), _ => None }
} Try / catch
match server_result {
Err(influxdb3_server::Error::Rustls(r)) => {
eprintln!("tls handshake/protocol failure: {r}");
// do not retry blindly; inspect peer TLS setup first
}
Err(e) => eprintln!("server error: {e}"),
Ok(v) => handle(v),
} Prevention
- Include the full certificate chain (leaf + intermediates) in the cert file
- Restrict server to TLS 1.2/1.3 and align client versions
- Test connectivity with openssl s_client before production rollout
- Do not mix plaintext HTTP clients with TLS-only ports; handle non-TLS connections on a separate listener
When it happens
Trigger: A TLS handshake failing at the rustls level when a client connects over HTTPS; malformed or unsupported TLS records from a peer; certificate validation issues surfaced at handshake time; rustls API misuse detected at runtime.
Common situations: Clients connecting with unsupported TLS versions or cipher suites; corrupted or mismatched certificate chains; clients speaking plaintext HTTP to a TLS-only port (or vice versa); intermediaries/proxies mangling TLS records.
Related errors
- failed to build an http client
- tls config error
- ' ' is a reserved column
- auto field family exists
- cache error
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/fe62fcd98fdf6281.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_server/src/lib.rs:87
#[error("database not found {db_name}")]
DatabaseNotFound { db_name: String },
#[error("datafusion error: {0}")]
DataFusion(#[from] datafusion::error::DataFusionError),
#[error("influxdb3_write error: {0}")]
InfluxDB3Write(#[from] influxdb3_write::Error),
#[error("from hex error: {0}")]
FromHex(#[from] hex::FromHexError),
#[error("io error: {0}")]
Io(#[from] std::io::Error),
#[error("tls config error: {0}")]
TlsConfig(String),
#[error("rustls error: {0}")]
Rustls(#[from] rustls::Error),
}
pub type Result<T, E = Error> = std::result::Result<T, E>;
#[derive(Debug, Clone)]
pub struct CommonServerState {
catalog: Arc<Catalog>,
metrics: Arc<metric::Registry>,
trace_exporter: Option<Arc<trace_exporters::export::AsyncExporter>>,
trace_header_parser: TraceHeaderParser,
telemetry_store: Arc<TelemetryStore>,
}
impl CommonServerState {
pub fn new(
catalog: Arc<Catalog>,
metrics: Arc<metric::Registry>,View on GitHub (pinned to 06200ef96b)