Encrypt Communication - 'net.ssl.allowInvalidCertificates != true'

Information

net.ssl.allowInvalidCertificates bypasses the validation checks for SSL certificates on other servers in the cluster and allows the use of invalid certificates.

Solution

Set net.ssl.allowInvalidCertificates to false.

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Unix

Control ID: 16ed9ed62f7629292b41a3ac776d960f8eb0682b9be56abf05c6520e445e59af