Encrypt Communication - config - 'net.ssl.weakCertificateValidation = false' - auth enabled

Information

net.ssl.weakCertificateValidation disables the requirement for SSL certificate validation. With the net.ssl.weakCertificateValidation option, the mongos or mongod will accept connections when the client does not present a certificate when establishing the connection.

Solution

Set net.ssl.weakCertificateValidation to false.

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Unix

Control ID: 17e01959fc780d1090366b6e5b2a8e16137b9c42ac8b4d87b1e43e4313aa6d76