SV-265948r1028630_rule
V-265948
SRG-APP-000441-DB-000378
MD7X-00-008800
CAT II
10
Stop the MongoDB instance if it is running.
Obtain a certificate from a valid DOD certificate authority to be used for encrypted data transmission.
Modify the MongoDB configuration file to include the following TLS configuration options:
net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true
Set "net.tls.mode" to the "requireTLS".
<PEM File> is the fullpathnames to the certificates used for the option.
Start/stop (restart) all mongod or mongos instances using the MongoDB configuration file (default location: /etc/mongod.conf).
If the data owner does not have a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process, this is not a finding.
If such a requirement is present, inspect the MongoDB configuration file (default location: /etc/mongod.conf) for the following entries:
net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true
If net.tls.mode is not set to "requireTLS", this is a finding.
V-265948
False
MD7X-00-008800
If the data owner does not have a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process, this is not a finding.
If such a requirement is present, inspect the MongoDB configuration file (default location: /etc/mongod.conf) for the following entries:
net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true
If net.tls.mode is not set to "requireTLS", this is a finding.
M
5637