SV-96585r2_rule
V-81871
SRG-APP-000176-DB-000068
MD3X-00-000360
CAT I
10
Run these commands:
"chown mongod:mongod /etc/ssl/mongodb.pem"
"chmod 600 /etc/ssl/mongodb.pem"
"chown mongod:mongod /etc/ssl/mongodbca.pem"
"chmod 600 /etc/ssl/mongodbca.pem"
In the MongoDB database configuration file (default location: /etc/mongod.conf), review the following parameters:
net:
ssl:
mode: requireSSL
PEMKeyFile: /etc/ssl/mongodb.pem
CAFile: /etc/ssl/mongodbca.pem
Verify ownership, group ownership, and permissions on the file given for PEMKeyFile (default 'mongodb.pem').
Run following command and review its output:
ls -al /etc/mongod.conf
typical output:
-rw------- 1 mongod mongod 566 Apr 26 20:20 /etc/mongod.conf
If the user owner is not "mongod", this is a finding.
If the group owner is not "mongod", this is a finding.
If the file is more permissive than "600", this is a finding.
Verify ownership, group ownership, and permissions on the file given for CAFile (default 'ca.pem').
If the user owner is not "mongod", this is a finding.
If the group owner is not "mongod", this is a finding.
If the file is more permissive than "600", this is a finding.
V-81871
False
MD3X-00-000360
In the MongoDB database configuration file (default location: /etc/mongod.conf), review the following parameters:
net:
ssl:
mode: requireSSL
PEMKeyFile: /etc/ssl/mongodb.pem
CAFile: /etc/ssl/mongodbca.pem
Verify ownership, group ownership, and permissions on the file given for PEMKeyFile (default 'mongodb.pem').
Run following command and review its output:
ls -al /etc/mongod.conf
typical output:
-rw------- 1 mongod mongod 566 Apr 26 20:20 /etc/mongod.conf
If the user owner is not "mongod", this is a finding.
If the group owner is not "mongod", this is a finding.
If the file is more permissive than "600", this is a finding.
Verify ownership, group ownership, and permissions on the file given for CAFile (default 'ca.pem').
If the user owner is not "mongod", this is a finding.
If the group owner is not "mongod", this is a finding.
If the file is more permissive than "600", this is a finding.
M
3265