Encrypt Communication - config - 'sslWeakCertificateValidation = false'

Information

sslWeakCertificateValidation disables the requirement for SSL certificate validation. With the net.ssl.weakCertificateValidation option, the mongos or mongod will accept connections when the client does not present a certificate when establishing the connection.

Solution

Set sslWeakCertificateValidation to false.

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Windows

Control ID: fc5d3b841a0c51408bca62528d6138ac86f38acf684b7e537faa8978318d6c04