官术网_书友最值得收藏!

Best practices for security

Security is always a multi-layered approach and these few recommendations do not form an exhaustive list, rather just the bare basics that need to be done in any MongoDB database:

  • HTTP status interface should be disabled.
  • REST API should be disabled.
  • JSON API should be disabled.
  • Connect to MongoDB using SSL.
  • Audit system activity.
  • Use a dedicated system user to access MongoDB with appropriate system level access
  • Disable server-side scripting if not needed. This will affect MapReduce, built-in db.group() commands, and $where operations. If these are not used in your codebase, it is better to disable server-side scripting at startup using the --noscripting parameter.
主站蜘蛛池模板: 桑日县| 青州市| 盖州市| 禄劝| 平阴县| 平阳县| 松江区| 谷城县| 罗田县| 巴青县| 来凤县| 诸城市| 科尔| 闽清县| 周口市| 香港 | 象山县| 惠州市| 宜章县| 延安市| 新疆| 信丰县| 崇州市| 施秉县| 昆山市| 湘阴县| 宣城市| 乳山市| 宿州市| 全椒县| 桦南县| 湾仔区| 祁门县| 泗水县| 黄骅市| 正安县| 新晃| 田东县| 大田县| 武胜县| 大安市|