0Pricing
MongoDB Academy · 课时

身份验证机制:SCRAM 与 x.509

学习者将启用 SCRAM-SHA-256 身份验证、创建数据库用户,并配置基于 x.509 证书的身份验证,用于集群内部身份验证。

身份验证机制:SCRAM 与 x.509 是 CoddyKit 上的免费 MongoDB Academy 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 MongoDB Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 MongoDB Academy 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Why Authentication Is Critical

By default, a freshly installed MongoDB instance listens on 0.0.0.0:27017 with no authentication required. Countless real-world breaches have resulted from developers leaving MongoDB exposed to the internet without auth enabled. Production deployments must always enable authentication so that only credentialed users and services can connect. MongoDB supports multiple authentication mechanisms — the two most important are SCRAM and x.509 certificates.

Enabling Authentication in mongod

Authentication is enabled by adding security.authorization: enabled to the mongod.conf configuration file (or passing --auth on the command line). Once enabled, every connection attempt must supply valid credentials. Before enabling auth on an existing deployment, always create an admin user first — otherwise you will lock yourself out.

# mongod.conf snippet
security:
  authorization: enabled

# Or start mongod with --auth flag
# mongod --auth --dbpath /data/db

Creating the First Admin User

Connect to MongoDB without auth while it is still in unauthenticated mode (or in localhost exception mode) to create the first user. Grant them the userAdminAnyDatabase role so they can create additional users. Then enable --auth and reconnect with credentials. The localhost exception allows an unauthenticated localhost connection only until the first user is created.

// Connect without auth, create admin user first
use admin
db.createUser({
  user: 'adminUser',
  pwd: 'StrongPassword123!',
  roles: [
    { role: 'userAdminAnyDatabase', db: 'admin' },
    { role: 'readWriteAnyDatabase', db: 'admin' }
  ]
})

// Reconnect with auth
// mongosh 'mongodb://adminUser:StrongPassword123!@localhost:27017'

SCRAM: The Default Auth Mechanism

SCRAM (Salted Challenge Response Authentication Mechanism) is MongoDB's default password-based authentication protocol. MongoDB uses SCRAM-SHA-256 (the newer, stronger variant) by default. SCRAM avoids sending the actual password over the network — the client and server perform a cryptographic handshake using salted hashes. Clients automatically negotiate the strongest SCRAM variant the server supports.

// Explicitly connect with SCRAM in Node.js
const { MongoClient } = require('mongodb')

const client = new MongoClient(
  'mongodb://myUser:myPassword@localhost:27017/mydb?authSource=admin',
  { authMechanism: 'SCRAM-SHA-256' }  // default, usually omitted
)

await client.connect()

Creating Application Users With Least Privilege

Each application service should have its own MongoDB user with only the permissions it needs. A read-only reporting service should only have the read role on the specific database. A write-heavy API should only have readWrite. Granting root or dbOwner to application accounts violates the principle of least privilege and amplifies breach impact.

// Read-only reporting user
use myApp
db.createUser({
  user: 'reportingSvc',
  pwd: 'SecurePass!456',
  roles: [{ role: 'read', db: 'myApp' }]
})

// API service user with read/write access
db.createUser({
  user: 'apiSvc',
  pwd: 'AnotherPass!789',
  roles: [{ role: 'readWrite', db: 'myApp' }]
})

x.509 Certificate-Based Authentication

x.509 certificates provide stronger authentication than passwords by using cryptographic key pairs. A client presents a certificate signed by a trusted Certificate Authority (CA) instead of a username/password. MongoDB maps the certificate's Subject Distinguished Name (DN) to a MongoDB user. This is the preferred mechanism for internal cluster member authentication (replicaset nodes authenticating with each other).

Configuring x.509 in mongod.conf

To enable x.509, you must configure TLS (the underlying transport) and set security.clusterAuthMode: x509 for intra-cluster auth. For client auth, set net.tls.CAFile to your CA certificate so MongoDB can verify client certificates. This requires generating a CA, signing certificates for each member and client, and distributing them securely.

# mongod.conf for x.509 client + cluster auth
net:
  tls:
    mode: requireTLS
    certificateKeyFile: /etc/ssl/server.pem
    CAFile: /etc/ssl/ca.pem

security:
  authorization: enabled
  clusterAuthMode: x509

Creating a User Mapped to an x.509 Certificate

When using x.509 client authentication, the MongoDB username must exactly match the Subject DN of the client certificate. Create the user in the $external database (not the regular admin or app database) since credentials are validated externally by the certificate, not by MongoDB's internal credential store.

// Create user mapped to certificate Subject DN
use $external
db.createUser({
  user: 'CN=apiService,OU=services,O=MyCompany,L=Istanbul,C=TR',
  roles: [{ role: 'readWrite', db: 'myApp' }]
})

// Connect using certificate in Node.js
const client = new MongoClient('mongodb://localhost:27017', {
  tls: true,
  tlsCertificateKeyFile: '/etc/ssl/client.pem',
  tlsCAFile: '/etc/ssl/ca.pem',
  authMechanism: 'MONGODB-X509'
})

Comparing SCRAM and x.509

SCRAM is simpler to set up — create a user with username/password and connect. It is suitable for most application services and developer access. x.509 is more complex (requires PKI infrastructure) but provides stronger guarantees: no passwords to rotate or leak, certificate revocation lists (CRLs) for immediate access revocation, and is mandatory for replica set member authentication in high-security environments.

Rotating Passwords and Updating Users

MongoDB provides db.updateUser() to change an existing user's password without dropping and recreating the account. In Atlas, rotate credentials through the Atlas UI or API. When rotating, update your application's connection string before changing the password to avoid a window of broken connectivity. Use connection string URI environment variables so password rotation requires only an env update and application restart.

// Rotate password for an existing user
use admin
db.updateUser('apiSvc', {
  pwd: 'NewStrongerPassword!2024'
})

// Or use changeUserPassword shorthand
db.changeUserPassword('apiSvc', 'NewStrongerPassword!2024')

Viewing and Removing Users

Audit your MongoDB users regularly. Use db.getUsers() to list all users in a database and db.getUser('name') for details on a specific account, including their assigned roles. Remove stale or compromised accounts immediately with db.dropUser(). On Atlas, the Users section of the Database Access panel provides a central inventory of all users across all clusters.

// List all users in current database
use myApp
db.getUsers()

// Get details of a specific user
db.getUser('apiSvc')

// Remove a user
db.dropUser('oldReportingService')

Quick Check

Test your understanding of MongoDB & NoSQL Databases concepts from this lesson.

Lesson Recap

In this lesson you learned: SCRAM-SHA-256 is MongoDB's default password-based auth mechanism and suitable for most application use cases, x.509 certificates provide stronger cryptographic authentication and are preferred for cluster-member internal auth, and always create users with least-privilege roles — application accounts should never hold admin-level permissions. Next up we dive into Role-Based Access Control.

常见问题解答

「身份验证机制:SCRAM 与 x.509」课时是免费的吗?

是的 — 「身份验证机制:SCRAM 与 x.509」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 MongoDB Academy 课程的其余内容,请升级到 CoddyKit PRO。 MongoDB Academy 课程共包含 4 节课。

「身份验证机制:SCRAM 与 x.509」这节课中我会学到什么?

学习者将启用 SCRAM-SHA-256 身份验证、创建数据库用户,并配置基于 x.509 证书的身份验证,用于集群内部身份验证。 你通过在浏览器中直接运行的动手代码来练习 MongoDB Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 MongoDB Academy 需要有经验吗?

无需任何先前经验。CoddyKit 上的 MongoDB Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。

「身份验证机制:SCRAM 与 x.509」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 MongoDB Academy 课中编写并运行代码吗?

能。每节 MongoDB Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 身份验证机制:SCRAM 与 x.509
  2. 基于角色的访问控制:内置角色与自定义角色
  3. 静态数据加密与传输中的 TLS
  4. 客户端字段级加密
← 返回 MongoDB Academy