官术网_书友最值得收藏!

Best practices for security

Security is always a multi-layered approach and these few recommendations do not form an exhaustive list, rather just the bare basics that need to be done in any MongoDB database:

  • HTTP status interface should be disabled.
  • REST API should be disabled.
  • JSON API should be disabled.
  • Connect to MongoDB using SSL.
  • Audit system activity.
  • Use a dedicated system user to access MongoDB with appropriate system level access
  • Disable server-side scripting if not needed. This will affect MapReduce, built-in db.group() commands, and $where operations. If these are not used in your codebase, it is better to disable server-side scripting at startup using the --noscripting parameter.
主站蜘蛛池模板: 凤凰县| 女性| 德庆县| 卫辉市| 桂东县| 苍溪县| 扎囊县| 攀枝花市| 凉山| 麟游县| 钟山县| 浦东新区| 宁武县| 新巴尔虎右旗| 葵青区| 大宁县| 武汉市| 江城| 定陶县| 长宁区| 海原县| 当涂县| 互助| 肥城市| 乌鲁木齐市| 六安市| 青铜峡市| 塔河县| 宿迁市| 乐业县| 琼海市| 林芝县| 高雄市| 长春市| 奉化市| 小金县| 静乐县| 临城县| 侯马市| 丹阳市| 兴和县|