SV-96557r1_rule
V-81843
SRG-APP-000023-DB-000001
MD3X-00-000010
CAT II
10
Edit the MongoDB configuration file (default location: /etc/mongod.con) to include the following:
security:
authorization: "enabled"
This will enable SCRAM-SHA-1 authentication (default).
Instruction on configuring the default authentication is provided here:
https://docs.mongodb.com/v3.4/tutorial/enable-authentication/
The high-level steps described by the above will require the following:
1. Start MongoDB without access control.
2. Connect to the instance.
3. Create the user administrator.
4. Restart the MongoDB instance with access control.
5. Connect and authenticate as the user administrator.
6. Create additional users as needed for your deployment.
Verify that the MongoDB configuration file (default location: /etc/mongod.conf) contains the following:
security:
authorization: "enabled"
If this parameter is not present, this is a finding.
V-81843
False
MD3X-00-000010
Verify that the MongoDB configuration file (default location: /etc/mongod.conf) contains the following:
security:
authorization: "enabled"
If this parameter is not present, this is a finding.
M
3265