STIGQter STIGQter: STIG Summary: MongoDB Enterprise Advanced 7.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

If passwords are used for authentication, MongoDB must transmit only encrypted representations of passwords.

DISA Rule

SV-265918r1028797_rule

Vulnerability Number

V-265918

Group Title

SRG-APP-000172-DB-000075

Rule Version

MD7X-00-003900

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

In the MongoDB database configuration file (default location: /etc/mongod.conf) ensure the following parameters are present in the "net.tls" (network TLS) section of the file and are configured correctly for the site and server:

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/server.pem
CAFile: /etc/ssl/ca.crt
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false

Restart the MongoDB service from the OS.

$ sudo systemctl restart mongod

More information for configuring TLS/SSL for MongoDB can be found here:
https://www.mongodb.com/docs/manual/tutorial/configure-ssl/

Check Contents

In the MongoDB database configuration file (default location: /etc/mongod.conf), verify the following parameters in the "net.tls" (network TLS) section of the file:

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/server.pem
CAFile: /etc/ssl/ca.crt
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false

If the "net.tls" parameter is not present, this is a finding.

If the "net.tls.certificateKeyFile" parameter is not present, this is a finding.

If the "net.tls.CAFile" parameter is not present, this is a finding.

If the "net.tls.allowInvalidCertificates" parameter is found and set to "true", this is a finding.

If the "net.tls.allowConnectionsWithoutCertificates" parameter is found and set to "true", this is a finding.

Vulnerability Number

V-265918

Documentable

False

Rule Version

MD7X-00-003900

Severity Override Guidance

In the MongoDB database configuration file (default location: /etc/mongod.conf), verify the following parameters in the "net.tls" (network TLS) section of the file:

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/server.pem
CAFile: /etc/ssl/ca.crt
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false

If the "net.tls" parameter is not present, this is a finding.

If the "net.tls.certificateKeyFile" parameter is not present, this is a finding.

If the "net.tls.CAFile" parameter is not present, this is a finding.

If the "net.tls.allowInvalidCertificates" parameter is found and set to "true", this is a finding.

If the "net.tls.allowConnectionsWithoutCertificates" parameter is found and set to "true", this is a finding.

Check Content Reference

M

Target Key

5637