2 Feb 2019

MongoDB Security Checklist

Enable access control and enforce authentication

Enable access control and specify an authentication mechanism — MongoDB’s default mechanism or an existing external framework. Authentication requires every client and server to provide valid credentials before connecting. In clustered deployments, enable authentication on every MongoDB server.

Configure role-based access control

Create a user administrator first, then create additional users — a unique MongoDB user for each person and application that accesses the system.

Create roles that define exactly the access a set of users needs, following the principle of least privilege, then assign users only the roles they need to do their job. A user can be a person or a client application.

Encrypt communication

Configure MongoDB to use TLS/SSL for all incoming and outgoing connections — between mongod and mongos components, and between every application and MongoDB.

Starting in version 4.0, MongoDB uses the native TLS/SSL OS libraries:

  • Windows: Secure Channel (Schannel)
  • Linux/BSD: OpenSSL
  • macOS: Secure Transport

Note: starting in version 4.0, MongoDB disables TLS 1.0 support on systems where TLS 1.1+ is available.

Encrypt and protect data

Starting with MongoDB Enterprise 3.2, the WiredTiger storage engine’s native Encryption at Rest can encrypt data at the storage layer.

If you’re not using WiredTiger’s encryption at rest, encrypt MongoDB data on each host using file-system, device, or physical encryption, and protect it with file-system permissions — this includes data files, configuration files, audit logs, and key files.

Limit network exposure

Run MongoDB in a trusted network environment, and limit the interfaces on which instances listen for incoming connections — allow only trusted clients to reach those interfaces and ports.

Note: starting with MongoDB 3.6, mongod and mongos bind to localhost by default. From versions 2.6 to 3.4, only the binaries from the official MongoDB RPM (Red Hat, CentOS, Fedora, and derivatives) and DEB (Debian, Ubuntu, and derivatives) packages did this by default.

Audit system activity

Track access and changes to database configuration and data. MongoDB Enterprise includes a system auditing facility that records events like user operations and connection events, permitting forensic analysis and letting administrators verify proper controls.

Run MongoDB with a dedicated user

Run MongoDB processes under a dedicated OS user account, with permission to access data but no unnecessary permissions beyond that.

Run MongoDB with secure configuration options

MongoDB can execute JavaScript for certain server-side operations — mapReduce, group, and $where. If you don’t use these, disable server-side scripting with the --noscripting option.

Use only the MongoDB wire protocol in production. Keep input validation enabled — the wireObjectCheck setting is on by default, ensuring every document stored by mongod is valid BSON.

Request a Security Technical Implementation Guide (where applicable)

The Security Technical Implementation Guide (STIG) contains security guidelines for deployments within the US Department of Defense. MongoDB Inc. provides its STIG on request where needed.

Consider security standards compliance

For applications needing HIPAA or PCI-DSS compliance, refer to the MongoDB Security Reference Architecture to see how to use MongoDB’s security capabilities to build compliant infrastructure.