Database audit fix

How to Configure & Enforce TLS/SSL in MongoDB Server

MongoDB offers four transport modes in mongod.conf, disabled, allowTLS, preferTLS and requireTLS, and only requireTLS refuses an unencrypted client. Set net.tls.mode to requireTLS with a certificateKeyFile, then restart mongod.

Hiren KalariyaLast reviewed: Sep 28, 2026Check mongodb-tls
Medium
severity
Yes
needs root or sudo
4
results it can return
5 of 5
checks in this audit

Every threshold on this page is transcribed from the database-security-transport-encryption audit script that CtrlOps runs, and a build check fails if the two ever disagree. See all 5 Transport Encryption checks, or how the audit runs.

Medium severityNeeds sudo

What this check reads

Greps /etc/mongod.conf for a mode: key set to either requireTLS or requireSSL, and that match on its own is the whole pass condition; no other mode counts. When neither appears, it takes the last line in the file matching bindIp and inspects the address on it. A bindIp containing 0.0.0.0 or :: turns the missing TLS into a FAIL, and any narrower address makes it a WARN.

When it applies

Runs only when MongoDB is detected (HAS_MG=1) and /etc/mongod.conf exists at that exact path; otherwise SKIP. Unlike most database checks it reads the file with a plain grep, so it works without root provided the file is readable, even though the script this check belongs to is marked as requiring sudo overall. It is a config grep and never queries the server, so TLS enabled by command-line flags is not seen. It matches only mode: requireTLS or mode: requireSSL; the weaker preferTLS and allowTLS modes are treated exactly like no TLS at all, which is intentional - they permit plaintext. When TLS is not required, the severity depends on the last bindIp line: 0.0.0.0 or :: gives FAIL, anything else WARN.

What each result means

Result thresholds this check applies
ResultWhenWhat it means
SKIPNot installed / config not foundNothing was read: either no MongoDB was detected or there is no file at `/etc/mongod.conf`, so the transport mode is unknown rather than acceptable.
PASS`net.tls.mode: requireTLS`The config file refuses plaintext client connections, assuming mongod has been restarted since that line was written.
FAILNo requireTLS and bound to all interfacesUnencrypted MongoDB traffic, credentials included, is reachable from the network right now.
WARNNo requireTLS, not bound to all interfacesNothing forces TLS, which is survivable only for as long as the bind address keeps the server off the network.

Why it matters

MongoDB's wire protocol sends credentials (SCRAM) and all documents in clear without TLS. net.tls.mode values: disabled, allowTLS, preferTLS, requireTLS. Only requireTLS refuses plaintext. MongoDB Security Checklist: "Encrypt Communication (TLS/SSL)". CIS MongoDB "Ensure Encryption of Data in Transit TLS or SSL".

Why it fails, and when it is wrong

  • preferTLS (used during migration) is reported as not required - correct, since it still accepts plaintext.
  • --tlsMode requireTLS on the command line is not seen.
  • The mode: grep is not scoped to the net.tls block; a mode: key elsewhere (unlikely) would match.
  • Same bindIp caveats as the binding check (bindIpAll not read).

How to fix it

net:
  tls:
    mode: requireTLS
    certificateKeyFile: /etc/ssl/mongodb.pem     # cert + key, 0600 mongodb
    CAFile: /etc/ssl/ca.pem

Restart mongod; update clients to --tls --tlsCAFile. Use preferTLS for a transition, then requireTLS.

Verify the fix

sudo grep -A5 -E '^[[:space:]]*(net|tls|ssl):' /etc/mongod.conf
# expected: mode: requireTLS, with certificateKeyFile set

# Ask the running server (authoritative):
mongosh --tls --tlsCAFile /path/ca.pem --quiet --eval 'db.adminCommand({getCmdLineOpts:1}).parsed.net'

# A plaintext connection must be refused:
mongosh --host <server> --quiet --eval 'db.runCommand({ping:1})'
# expected: connection closed / TLS required

# Inspect the certificate the server presents:
openssl s_client -connect <server>:27017 -brief </dev/null

Debugging

The server uses a different config path; find it with ps -o args= -C mongod. The check reads only /etc/mongod.conf.

You are probably on preferTLS or allowTLS. Both allow plaintext connections and are deliberately not accepted here. Confirm with sudo grep -n mode: /etc/mongod.conf; move to requireTLS once every client is ready.

That means no requireTLS and a bindIp containing 0.0.0.0 or ::. Fix either half and the severity drops; fix both and it passes. See MongoDB Network Binding.

The config was edited without a restart, or the server was started with overriding command-line options. Compare getCmdLineOpts with the file, then systemctl restart mongod.

Each client now needs --tls and a CA file it trusts. Roll it out by moving to preferTLS first, migrating the clients, then switching to requireTLS (accepting that the check reports the intermediate state as a finding).

Nearly always the certificate file: net.tls.certificateKeyFile must contain the key and certificate concatenated in one PEM, readable by the mongodb user. The reason is in journalctl -u mongod.

Sources

How the script reads this

Next

Re-run the Transport Encryption audit after applying the fix and confirm this check moves to PASS. CtrlOps runs all 5 checks over your existing SSH connection and scores the result, so the change is visible without reading another config file.

All 5 Transport Encryption fixes
Audit your fleet

Find every one of these on every server, in one click

CtrlOps runs this audit over your existing SSH connection - no agents, no scripts to manage. $7/user/month after a 1 month free trial - no credit card required.

Windows

✓ Start instantly·✓ No credit card·✓ No sneaky autorenewals