STIGQter STIGQter: STIG Summary: MongoDB Enterprise Advanced 3.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jul 2020:

MongoDB must maintain the confidentiality and integrity of information during reception.

DISA Rule

SV-96637r1_rule

Vulnerability Number

V-81923

Group Title

SRG-APP-000442-DB-000379

Rule Version

MD3X-00-000770

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Obtain a certificate from a valid DoD certificate authority to be used for encrypted data transmission.

Modify the MongoDB configuration file (default location: /etc/mongod.conf) with the network configuration options.

net:
ssl:
mode: requireSSL
PEMKeyFile: /etc/ssl/mongodb.pem

Set "net.ssl.mode" to the "requireSSL".
Set "net.ssl.KeyFile" to the full path of the certificate (.pem) file.

Start/stop (restart) all mongod or mongos instances using the MongoDB configuration file (default location: /etc/mongod.conf).

Check Contents

If the data owner does not have a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process, this is not a finding.

If such strict requirement for ensure data integrity and confidentially is present, inspect the MongoDB configuration file (default location: /etc/mongod.conf) for the following entries:

net:
ssl:
mode: requireSSL
PEMKeyFile: /etc/ssl/mongodb.pem

If net.ssl.mode is not set to "requireSSL", this is a finding.

Vulnerability Number

V-81923

Documentable

False

Rule Version

MD3X-00-000770

Severity Override Guidance

If the data owner does not have a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process, this is not a finding.

If such strict requirement for ensure data integrity and confidentially is present, inspect the MongoDB configuration file (default location: /etc/mongod.conf) for the following entries:

net:
ssl:
mode: requireSSL
PEMKeyFile: /etc/ssl/mongodb.pem

If net.ssl.mode is not set to "requireSSL", this is a finding.

Check Content Reference

M

Target Key

3265

Comments