Encrypt Communication - 'net.ssl.allowInvalidCertificates != true'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

net.ssl.allowInvalidCertificates bypasses the validation checks for SSL certificates on other servers in the cluster and allows the use of invalid certificates.

Solution

Set net.ssl.allowInvalidCertificates to false.

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12

Plugin: Unix

Control ID: 16ed9ed62f7629292b41a3ac776d960f8eb0682b9be56abf05c6520e445e59af