認証メカニズム:SCRAM と x.509
SCRAM-SHA-256 認証を有効にし、データベースユーザーを作成して、内部クラスター認証用の x.509 証明書ベース認証を設定します。
「認証メカニズム:SCRAM と x.509」はCoddyKit上の無料MongoDB Academyレッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはMongoDB Academy学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 MongoDB Academyコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Why Authentication Is Critical
By default, a freshly installed MongoDB instance listens on 0.0.0.0:27017 with no authentication required. Countless real-world breaches have resulted from developers leaving MongoDB exposed to the internet without auth enabled. Production deployments must always enable authentication so that only credentialed users and services can connect. MongoDB supports multiple authentication mechanisms — the two most important are SCRAM and x.509 certificates.
Enabling Authentication in mongod
Authentication is enabled by adding security.authorization: enabled to the mongod.conf configuration file (or passing --auth on the command line). Once enabled, every connection attempt must supply valid credentials. Before enabling auth on an existing deployment, always create an admin user first — otherwise you will lock yourself out.
# mongod.conf snippet
security:
authorization: enabled
# Or start mongod with --auth flag
# mongod --auth --dbpath /data/dbCreating the First Admin User
Connect to MongoDB without auth while it is still in unauthenticated mode (or in localhost exception mode) to create the first user. Grant them the userAdminAnyDatabase role so they can create additional users. Then enable --auth and reconnect with credentials. The localhost exception allows an unauthenticated localhost connection only until the first user is created.
// Connect without auth, create admin user first
use admin
db.createUser({
user: 'adminUser',
pwd: 'StrongPassword123!',
roles: [
{ role: 'userAdminAnyDatabase', db: 'admin' },
{ role: 'readWriteAnyDatabase', db: 'admin' }
]
})
// Reconnect with auth
// mongosh 'mongodb://adminUser:StrongPassword123!@localhost:27017'SCRAM: The Default Auth Mechanism
SCRAM (Salted Challenge Response Authentication Mechanism) is MongoDB's default password-based authentication protocol. MongoDB uses SCRAM-SHA-256 (the newer, stronger variant) by default. SCRAM avoids sending the actual password over the network — the client and server perform a cryptographic handshake using salted hashes. Clients automatically negotiate the strongest SCRAM variant the server supports.
// Explicitly connect with SCRAM in Node.js
const { MongoClient } = require('mongodb')
const client = new MongoClient(
'mongodb://myUser:myPassword@localhost:27017/mydb?authSource=admin',
{ authMechanism: 'SCRAM-SHA-256' } // default, usually omitted
)
await client.connect()Creating Application Users With Least Privilege
Each application service should have its own MongoDB user with only the permissions it needs. A read-only reporting service should only have the read role on the specific database. A write-heavy API should only have readWrite. Granting root or dbOwner to application accounts violates the principle of least privilege and amplifies breach impact.
// Read-only reporting user
use myApp
db.createUser({
user: 'reportingSvc',
pwd: 'SecurePass!456',
roles: [{ role: 'read', db: 'myApp' }]
})
// API service user with read/write access
db.createUser({
user: 'apiSvc',
pwd: 'AnotherPass!789',
roles: [{ role: 'readWrite', db: 'myApp' }]
})x.509 Certificate-Based Authentication
x.509 certificates provide stronger authentication than passwords by using cryptographic key pairs. A client presents a certificate signed by a trusted Certificate Authority (CA) instead of a username/password. MongoDB maps the certificate's Subject Distinguished Name (DN) to a MongoDB user. This is the preferred mechanism for internal cluster member authentication (replicaset nodes authenticating with each other).
Configuring x.509 in mongod.conf
To enable x.509, you must configure TLS (the underlying transport) and set security.clusterAuthMode: x509 for intra-cluster auth. For client auth, set net.tls.CAFile to your CA certificate so MongoDB can verify client certificates. This requires generating a CA, signing certificates for each member and client, and distributing them securely.
# mongod.conf for x.509 client + cluster auth
net:
tls:
mode: requireTLS
certificateKeyFile: /etc/ssl/server.pem
CAFile: /etc/ssl/ca.pem
security:
authorization: enabled
clusterAuthMode: x509Creating a User Mapped to an x.509 Certificate
When using x.509 client authentication, the MongoDB username must exactly match the Subject DN of the client certificate. Create the user in the $external database (not the regular admin or app database) since credentials are validated externally by the certificate, not by MongoDB's internal credential store.
// Create user mapped to certificate Subject DN
use $external
db.createUser({
user: 'CN=apiService,OU=services,O=MyCompany,L=Istanbul,C=TR',
roles: [{ role: 'readWrite', db: 'myApp' }]
})
// Connect using certificate in Node.js
const client = new MongoClient('mongodb://localhost:27017', {
tls: true,
tlsCertificateKeyFile: '/etc/ssl/client.pem',
tlsCAFile: '/etc/ssl/ca.pem',
authMechanism: 'MONGODB-X509'
})Comparing SCRAM and x.509
SCRAM is simpler to set up — create a user with username/password and connect. It is suitable for most application services and developer access. x.509 is more complex (requires PKI infrastructure) but provides stronger guarantees: no passwords to rotate or leak, certificate revocation lists (CRLs) for immediate access revocation, and is mandatory for replica set member authentication in high-security environments.
Rotating Passwords and Updating Users
MongoDB provides db.updateUser() to change an existing user's password without dropping and recreating the account. In Atlas, rotate credentials through the Atlas UI or API. When rotating, update your application's connection string before changing the password to avoid a window of broken connectivity. Use connection string URI environment variables so password rotation requires only an env update and application restart.
// Rotate password for an existing user
use admin
db.updateUser('apiSvc', {
pwd: 'NewStrongerPassword!2024'
})
// Or use changeUserPassword shorthand
db.changeUserPassword('apiSvc', 'NewStrongerPassword!2024')Viewing and Removing Users
Audit your MongoDB users regularly. Use db.getUsers() to list all users in a database and db.getUser('name') for details on a specific account, including their assigned roles. Remove stale or compromised accounts immediately with db.dropUser(). On Atlas, the Users section of the Database Access panel provides a central inventory of all users across all clusters.
// List all users in current database
use myApp
db.getUsers()
// Get details of a specific user
db.getUser('apiSvc')
// Remove a user
db.dropUser('oldReportingService')Quick Check
Test your understanding of MongoDB & NoSQL Databases concepts from this lesson.
Lesson Recap
In this lesson you learned: SCRAM-SHA-256 is MongoDB's default password-based auth mechanism and suitable for most application use cases, x.509 certificates provide stronger cryptographic authentication and are preferred for cluster-member internal auth, and always create users with least-privilege roles — application accounts should never hold admin-level permissions. Next up we dive into Role-Based Access Control.
よくある質問
「認証メカニズム:SCRAM と x.509」レッスンは無料ですか?
はい。「認証メカニズム:SCRAM と x.509」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、MongoDB Academyコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 MongoDB Academyコースには全4レッスンが含まれています。
「認証メカニズム:SCRAM と x.509」で何を学びますか?
SCRAM-SHA-256 認証を有効にし、データベースユーザーを作成して、内部クラスター認証用の x.509 証明書ベース認証を設定します。 ブラウザで直接実行するハンズオンコードでMongoDB Academyを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
MongoDB Academyを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのMongoDB Academyは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。
「認証メカニズム:SCRAM と x.509」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このMongoDB Academyレッスンでコードを書いて実行できますか?
はい。すべてのMongoDB Academyレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- 認証メカニズム:SCRAM と x.509
- ロールベースアクセス制御:組み込みロールとカスタムロール
- 保存時の暗号化と転送中の TLS
- クライアント側フィールドレベル暗号化