STIGQter STIGQter: STIG Summary: MongoDB Enterprise Advanced 8.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

If passwords are used for authentication, MongoDB must transmit only encrypted representations of passwords.

DISA Rule

SV-279350r1179454_rule

Vulnerability Number

V-279350

Group Title

SRG-APP-000172-DB-000075

Rule Version

MD8X-00-003700

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

In the MongoDB database configuration file (default location /etc/mongod.conf), ensure the following parameters are present in the "net.tls" (network TLS) section of the file and are configured correctly for the site and server:

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/server.pem
CAFile: /etc/ssl/ca.crt
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false

Restart the MongoDB service from the OS.

$ sudo systemctl restart mongod

More information for configuring TLS/SSL for MongoDB can be found here:
https://www.mongodb.com/docs/manual/tutorial/configure-ssl/

Check Contents

In the MongoDB database configuration file (default location /etc/mongod.conf), verify the following parameters in the "net.tls" (network TLS) section of the file:

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/server.pem
CAFile: /etc/ssl/ca.crt
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false

If the "net.tls" parameter is not present, this is a finding.

If the "net.tls.certificateKeyFile" parameter is not present, this is a finding.

If the "net.tls.CAFile" parameter is not present, this is a finding.

If the "net.tls.allowInvalidCertificates" parameter is found and set to "true", this is a finding.

If the "net.tls.allowConnectionsWithoutCertificates" parameter is found and set to "true", this is a finding.

Vulnerability Number

V-279350

Documentable

False

Rule Version

MD8X-00-003700

Severity Override Guidance

In the MongoDB database configuration file (default location /etc/mongod.conf), verify the following parameters in the "net.tls" (network TLS) section of the file:

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/server.pem
CAFile: /etc/ssl/ca.crt
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false

If the "net.tls" parameter is not present, this is a finding.

If the "net.tls.certificateKeyFile" parameter is not present, this is a finding.

If the "net.tls.CAFile" parameter is not present, this is a finding.

If the "net.tls.allowInvalidCertificates" parameter is found and set to "true", this is a finding.

If the "net.tls.allowConnectionsWithoutCertificates" parameter is found and set to "true", this is a finding.

Check Content Reference

M

Target Key

5728