What this check reads
Greps /etc/mongod.conf for a mode: key set to either requireTLS or requireSSL, and that match on its own is the whole pass condition; no other mode counts. When neither appears, it takes the last line in the file matching bindIp and inspects the address on it. A bindIp containing 0.0.0.0 or :: turns the missing TLS into a FAIL, and any narrower address makes it a WARN.
When it applies
Runs only when MongoDB is detected (HAS_MG=1) and /etc/mongod.conf exists at that exact path; otherwise SKIP. Unlike most database checks it reads the file with a plain grep, so it works without root provided the file is readable, even though the script this check belongs to is marked as requiring sudo overall. It is a config grep and never queries the server, so TLS enabled by command-line flags is not seen. It matches only mode: requireTLS or mode: requireSSL; the weaker preferTLS and allowTLS modes are treated exactly like no TLS at all, which is intentional - they permit plaintext. When TLS is not required, the severity depends on the last bindIp line: 0.0.0.0 or :: gives FAIL, anything else WARN.
What each result means
| Result | When | What it means |
|---|---|---|
| SKIP | Not installed / config not found | Nothing was read: either no MongoDB was detected or there is no file at `/etc/mongod.conf`, so the transport mode is unknown rather than acceptable. |
| PASS | `net.tls.mode: requireTLS` | The config file refuses plaintext client connections, assuming mongod has been restarted since that line was written. |
| FAIL | No requireTLS and bound to all interfaces | Unencrypted MongoDB traffic, credentials included, is reachable from the network right now. |
| WARN | No requireTLS, not bound to all interfaces | Nothing forces TLS, which is survivable only for as long as the bind address keeps the server off the network. |
Why it matters
MongoDB's wire protocol sends credentials (SCRAM) and all documents in clear without TLS. net.tls.mode values: disabled, allowTLS, preferTLS, requireTLS. Only requireTLS refuses plaintext. MongoDB Security Checklist: "Encrypt Communication (TLS/SSL)". CIS MongoDB "Ensure Encryption of Data in Transit TLS or SSL".
Why it fails, and when it is wrong
preferTLS(used during migration) is reported as not required - correct, since it still accepts plaintext.--tlsMode requireTLSon the command line is not seen.- The
mode:grep is not scoped to thenet.tlsblock; amode:key elsewhere (unlikely) would match. - Same
bindIpcaveats as the binding check (bindIpAllnot read).
How to fix it
net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/mongodb.pem # cert + key, 0600 mongodb
CAFile: /etc/ssl/ca.pemRestart mongod; update clients to --tls --tlsCAFile. Use preferTLS for a transition, then requireTLS.
Verify the fix
sudo grep -A5 -E '^[[:space:]]*(net|tls|ssl):' /etc/mongod.conf
# expected: mode: requireTLS, with certificateKeyFile set
# Ask the running server (authoritative):
mongosh --tls --tlsCAFile /path/ca.pem --quiet --eval 'db.adminCommand({getCmdLineOpts:1}).parsed.net'
# A plaintext connection must be refused:
mongosh --host <server> --quiet --eval 'db.runCommand({ping:1})'
# expected: connection closed / TLS required
# Inspect the certificate the server presents:
openssl s_client -connect <server>:27017 -brief </dev/nullDebugging
The server uses a different config path; find it with ps -o args= -C mongod. The check reads only /etc/mongod.conf.
You are probably on preferTLS or allowTLS. Both allow plaintext connections and are deliberately not accepted here. Confirm with sudo grep -n mode: /etc/mongod.conf; move to requireTLS once every client is ready.
That means no requireTLS and a bindIp containing 0.0.0.0 or ::. Fix either half and the severity drops; fix both and it passes. See MongoDB Network Binding.
The config was edited without a restart, or the server was started with overriding command-line options. Compare getCmdLineOpts with the file, then systemctl restart mongod.
Each client now needs --tls and a CA file it trusts. Roll it out by moving to preferTLS first, migrating the clients, then switching to requireTLS (accepting that the check reports the intermediate state as a finding).
Nearly always the certificate file: net.tls.certificateKeyFile must contain the key and certificate concatenated in one PEM, readable by the mongodb user. The reason is in journalctl -u mongod.
Sources
- MongoDB: Configure mongod and mongos for TLS/SSL
- MongoDB: net.tls.mode
- MongoDB: Upgrade a Cluster to Use TLS/SSL (preferTLS rollout)
- MongoDB: Security Checklist
How the script reads this
Next
Re-run the Transport Encryption audit after applying the fix and confirm this check moves to PASS. CtrlOps runs all 5 checks over your existing SSH connection and scores the result, so the change is visible without reading another config file.
All 5 Transport Encryption fixes