SV-96579r1_rule
V-81865
SRG-APP-000164-DB-000401
MD3X-00-000320
CAT II
10
Either configure MongoDB for Native LDAP authentication where LDAP is configured to enforce password complexity and lifetime.
OR
Configure MongoDB Kerberos authentication where Kerberos is configured to enforce password complexity and lifetime.
If MongoDB is using Native LDAP authentication where the LDAP server is configured to enforce password complexity and lifetime, this is not a finding.
If MongoDB is using Kerberos authentication where Kerberos is configured to enforce password complexity and lifetime, this is not a finding.
If MongoDB is configured for SCRAM-SHA1, MONGODB-CR, LDAP Proxy authentication, this is a finding.
See: https://docs.mongodb.com/v3.4/core/authentication/#authentication-methods
V-81865
False
MD3X-00-000320
If MongoDB is using Native LDAP authentication where the LDAP server is configured to enforce password complexity and lifetime, this is not a finding.
If MongoDB is using Kerberos authentication where Kerberos is configured to enforce password complexity and lifetime, this is not a finding.
If MongoDB is configured for SCRAM-SHA1, MONGODB-CR, LDAP Proxy authentication, this is a finding.
See: https://docs.mongodb.com/v3.4/core/authentication/#authentication-methods
M
3265