Encrypt Communication - config - 'net.ssl.weakCertificateValidation = false' - auth not enabled

Information

net.ssl.weakCertificateValidation disables the requirement for SSL certificate validation. With the net.ssl.weakCertificateValidation option, the mongos or mongod will accept connections when the client does not present a certificate when establishing the connection.

Solution

Set net.ssl.weakCertificateValidation to false.

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Unix

Control ID: 559637b151a14b60e01178cea40513d59618eaa63c42ae4cc2e414d6c6163606