官术网_书友最值得收藏!

Best practices for security

Security is always a multi-layered approach and these few recommendations do not form an exhaustive list, rather just the bare basics that need to be done in any MongoDB database:

  • HTTP status interface should be disabled.
  • REST API should be disabled.
  • JSON API should be disabled.
  • Connect to MongoDB using SSL.
  • Audit system activity.
  • Use a dedicated system user to access MongoDB with appropriate system level access
  • Disable server-side scripting if not needed. This will affect MapReduce, built-in db.group() commands, and $where operations. If these are not used in your codebase, it is better to disable server-side scripting at startup using the --noscripting parameter.
主站蜘蛛池模板: 子长县| 梧州市| 嘉兴市| 乌拉特前旗| 林周县| 灌云县| 濉溪县| 栖霞市| 莱西市| 霍山县| 道孚县| 罗田县| 龙海市| 涞源县| 历史| 册亨县| 叙永县| 福安市| 年辖:市辖区| 介休市| 三原县| 桂林市| 永安市| 湛江市| 玉环县| 循化| 红原县| 嘉定区| 静宁县| 梨树县| 阿拉善右旗| 木兰县| 通山县| 石阡县| 保定市| 洪泽县| 荥阳市| 从江县| 清远市| 合阳县| 潞西市|