STIGQter STIGQter: STIG Summary: MongoDB Enterprise Advanced 7.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

MongoDB must maintain the confidentiality and integrity of information during preparation for transmission.

DISA Rule

SV-265948r1028630_rule

Vulnerability Number

V-265948

Group Title

SRG-APP-000441-DB-000378

Rule Version

MD7X-00-008800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Stop the MongoDB instance if it is running.

Obtain a certificate from a valid DOD certificate authority to be used for encrypted data transmission.

Modify the MongoDB configuration file to include the following TLS configuration options:

net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true

Set "net.tls.mode" to the "requireTLS".
<PEM File> is the fullpathnames to the certificates used for the option.

Start/stop (restart) all mongod or mongos instances using the MongoDB configuration file (default location: /etc/mongod.conf).

Check Contents

If the data owner does not have a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process, this is not a finding.

If such a requirement is present, inspect the MongoDB configuration file (default location: /etc/mongod.conf) for the following entries:

net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true

If net.tls.mode is not set to "requireTLS", this is a finding.

Vulnerability Number

V-265948

Documentable

False

Rule Version

MD7X-00-008800

Severity Override Guidance

If the data owner does not have a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process, this is not a finding.

If such a requirement is present, inspect the MongoDB configuration file (default location: /etc/mongod.conf) for the following entries:

net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true

If net.tls.mode is not set to "requireTLS", this is a finding.

Check Content Reference

M

Target Key

5637