在CentOS上为MongoDB设置安全性是非常重要的,以下是一些基本步骤和建议:
/etc/mongod.conf。security:
authorization: enabled
sudo systemctl restart mongod
mongo
use admin
db.createUser({
user: "admin",
pwd: "your_strong_password",
roles: [ { role: "userAdminAnyDatabase", db: "admin" } ]
})
db.grantRolesToUser("admin", [ { role: "userAdminAnyDatabase", db: "admin" } ])
use your_database
db.createUser({
user: "your_username",
pwd: "your_password",
roles: [ { role: "readWrite", db: "your_database" } ]
})
db.grantRolesToUser("your_username", [ { role: "readWrite", db: "your_database" } ])
sudo firewall-cmd --permanent --zone=public --add-port=27017/tcp
sudo firewall-cmd --reload
bindIp 设置为 127.0.0.1,仅允许本地连接:net:
port: 27017
bindIp: 127.0.0.1
/etc/mongod.conf中配置SSL/TLS:sudo openssl req -newkey rsa:2048 -new -nodes -x509 -days 3650 -keyout /etc/ssl/mongodb.key -out /etc/ssl/mongodb.crt
net:
ssl:
mode: requireSSL
PEMKeyFile: /etc/ssl/mongodb.key
CAFile: /etc/ssl/mongodb.crt