SV-279389r1179334_rule
V-279389
SRG-APP-000441-DB-000378
MD8X-00-008400
CAT II
10
Stop the MongoDB instance if it is running.
Obtain a certificate from a valid DOD certificate authority to be used for encrypted data transmission.
Modify the MongoDB configuration file to include the following TLS configuration options:
net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true
Set "net.tls.mode" to the "requireTLS".
<PEM File> is the fullpathnames to the certificates used for the option.
Start/stop (restart) all mongod or mongos instances using the MongoDB configuration file (default location: /etc/mongod.conf).
If the data owner does not have a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process, this is not a finding.
If such a requirement is present, inspect the MongoDB configuration file (default location: /etc/mongod.conf) for the following entries:
net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true
If net.tls.mode is not set to "requireTLS", this is a finding.
V-279389
False
MD8X-00-008400
If the data owner does not have a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process, this is not a finding.
If such a requirement is present, inspect the MongoDB configuration file (default location: /etc/mongod.conf) for the following entries:
net:
tls:
mode: requireTLS
certificateKeyFile: <PEM File>
CAFile: <PEM File>
allowInvalidCertificates: false
allowConnectionsWithoutCertificates: false
FIPSMode: true
If net.tls.mode is not set to "requireTLS", this is a finding.
M
5728