SV-279412r1179403_rule
V-279412
SRG-APP-000915-DB-000310
MD8X-00-014100
CAT II
10
Check the MongoDB configuration file (default location /etc/mongod.conf) for a key named "net.tls.CAFile".
Example shown below:
net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/mongodb.pem
CAFile: /etc/ssl/caToValidateClientCertificates.pem
ocsp:
enabled: true
responderURL: <your organization's OCSP responder URL>
Run the following commands on the file indicated by this key:
chmod 600 /etc/ssl/caToValidateClientCertificates.pem
Check the MongoDB configuration file (default location /etc/mongod.conf) for a key named "net.tls.CAFile".
Example shown below:
net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/mongodb.pem
CAFile: /etc/ssl/caToValidateClientCertificates.pem
ocsp:
enabled: true
responderURL: <your organization's OCSP responder URL>
Run the following command on the file indicated by this key:
stat /etc/ssl/caToValidateClientCertificates.pem
If the output does not show file permissions of "-rw-------", this is a finding.
V-279412
False
MD8X-00-014100
Check the MongoDB configuration file (default location /etc/mongod.conf) for a key named "net.tls.CAFile".
Example shown below:
net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/mongodb.pem
CAFile: /etc/ssl/caToValidateClientCertificates.pem
ocsp:
enabled: true
responderURL: <your organization's OCSP responder URL>
Run the following command on the file indicated by this key:
stat /etc/ssl/caToValidateClientCertificates.pem
If the output does not show file permissions of "-rw-------", this is a finding.
M
5728