2 Feb 2019

MongoDB Security

Introduction

MongoDB provides features like authentication, access control, and encryption to secure your deployments. Some key areas:

Authentication — Authentication, SCRAM, x.509.

Authorization — Role-Based Access Control, Enable Access Control, Manage Users and Roles.

TLS/SSL — Transport encryption, configuring mongod/mongos for TLS/SSL, and client-side TLS/SSL configuration.

Enterprise only — Kerberos authentication, LDAP proxy authentication, Encryption at Rest, Auditing.

Encryption — Client-Side Field Level Encryption.

MongoDB also provides a Security Checklist of recommended actions for protecting a deployment.

Pre-production checklist

Enable access control and enforce authentication

Enable access control and pick an authentication mechanism. MongoDB Community supports:

  • SCRAM (default)
  • x.509 certificate authentication

MongoDB Atlas and Enterprise additionally support LDAP proxy authentication and Kerberos authentication, letting MongoDB integrate with an existing authentication system.

Configure role-based access control

Create a user administrator first, then additional users — a unique MongoDB user per person or application. Follow the principle of least privilege: define roles with the exact access rights a set of users needs, then assign users only those roles.

Encrypt communication (TLS/SSL)

Configure TLS/SSL for all incoming and outgoing connections, between mongod/mongos components and between applications and MongoDB. MongoDB uses the native TLS/SSL OS libraries:

PlatformTLS/SSL library
WindowsSecure Channel (Schannel)
Linux/BSDOpenSSL
macOSSecure Transport

Encrypt and protect data

  • Encrypt data at the storage layer with WiredTiger’s native Encryption at Rest.
  • Otherwise, encrypt MongoDB data on each host with file-system, device, or physical encryption (e.g. dm-crypt), and protect it with file-system permissions — data files, config files, audit logs, and key files.
  • Use Client-Side Field Level Encryption to encrypt specific document fields on the application side before they go over the wire.
  • Collect logs to a central log store — they include database authentication attempts with source IP addresses.

Limit network exposure

  • Run MongoDB in a trusted network environment, with a firewall or security groups controlling inbound/outbound traffic.
  • Disable direct SSH root access.
  • Allow only trusted clients to reach the network interfaces and ports MongoDB listens on.

Audit system activity

Track access and configuration/data changes. MongoDB Enterprise’s system auditing facility can record events like user operations and connections, supporting forensic analysis and letting administrators filter for specific events such as authentication.

Run MongoDB with a dedicated user

Run MongoDB processes under a dedicated OS account with just enough permission to access data — nothing more.

Run MongoDB with secure configuration options

Server-side scripting covers mapReduce, $where, $accumulator, and $function — if you don’t use these, disable it with --noscripting.

Keep input validation enabled — net.wireObjectCheck is on by default, ensuring every document mongod stores is valid BSON.

Request a Security Technical Implementation Guide (where applicable)

The STIG contains security guidelines for US Department of Defense deployments; MongoDB Inc. provides its STIG on request.

Consider security standards compliance

For HIPAA or PCI-DSS needs, see the MongoDB Security Reference Architecture for how to use MongoDB’s security capabilities to build compliant infrastructure.

Periodic / ongoing production checks

  • Periodically check for MongoDB CVEs and upgrade.
  • Track MongoDB end-of-life dates and upgrade as needed — generally, stay close to the latest version.
  • Make sure your information security policies and procedures extend to your MongoDB installation:
    • Periodically patch the machine.
    • Review policy/procedure changes, especially to network rules, to avoid accidentally exposing MongoDB to the internet.
    • Review MongoDB database users and rotate them periodically.