STIGQter STIGQter: STIG Summary: MongoDB Enterprise Advanced 7.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

MongoDB must enforce authorized access to all PKI private keys stored/used by MongoDB.

DISA Rule

SV-265919r1028543_rule

Vulnerability Number

V-265919

Group Title

SRG-APP-000176-DB-000068

Rule Version

MD7X-00-004100

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Run these commands:

chown mongodb:mongodb /etc/ssl/mongodb.pem
chmod 600 /etc/ssl/mongodb.pem
chown mongodb:mongodb /etc/ssl/mongodbca.pem
chmod 600 /etc/ssl/mongodbca.pem

Check Contents

In the MongoDB database configuration file (default location: /etc/mongod.conf), review the following parameters:

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/mongodb.pem
CAFile: /etc/ssl/mongodbca.pem

Verify ownership, group ownership, and permissions for the MongoDB config file (default: /etc/mongod.conf), the certificateKeyFile (default '/etc/ssl/mongodb.pem'), and the CAFile (default '/etc/ssl/mongodbca.pem').

For each file:

Run following command and review its output:
ls -al <filepath>

example output:
-rw------- 1 mongodb mongodb 566 Apr 26 20:20 <filepath>

If the user owner is not "mongodb", this is a finding.

If the group owner is not "mongodb", this is a finding.

If the file is more permissive than "600", this is a finding.

Vulnerability Number

V-265919

Documentable

False

Rule Version

MD7X-00-004100

Severity Override Guidance

In the MongoDB database configuration file (default location: /etc/mongod.conf), review the following parameters:

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/mongodb.pem
CAFile: /etc/ssl/mongodbca.pem

Verify ownership, group ownership, and permissions for the MongoDB config file (default: /etc/mongod.conf), the certificateKeyFile (default '/etc/ssl/mongodb.pem'), and the CAFile (default '/etc/ssl/mongodbca.pem').

For each file:

Run following command and review its output:
ls -al <filepath>

example output:
-rw------- 1 mongodb mongodb 566 Apr 26 20:20 <filepath>

If the user owner is not "mongodb", this is a finding.

If the group owner is not "mongodb", this is a finding.

If the file is more permissive than "600", this is a finding.

Check Content Reference

M

Target Key

5637