Encrypt Communication - config - 'sslWeakCertificateValidation = false'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

sslWeakCertificateValidation disables the requirement for SSL certificate validation. With the net.ssl.weakCertificateValidation option, the mongos or mongod will accept connections when the client does not present a certificate when establishing the connection.

Solution

Set sslWeakCertificateValidation to false.

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Windows

Control ID: fc5d3b841a0c51408bca62528d6138ac86f38acf684b7e537faa8978318d6c04