Encrypt Communication - config - 'net.ssl.weakCertificateValidation = false'

Information

net.ssl.weakCertificateValidation disables the requirement for SSL certificate validation. With the net.ssl.weakCertificateValidation option, the mongos or mongod will accept connections when the client does not present a certificate when establishing the connection.

Solution

Set net.ssl.weakCertificateValidation to false.

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Windows

Control ID: 4088403d93d0520333786159d3c8ec299bf612b93175fc0a8710e91b7cb528b6