Uploaded image for project: 'Documentation'
  1. Documentation
  2. DOCS-4210

Clarify use of mms.remoteIp.header property

    XMLWordPrintableJSON

Details

    Description

      This page https://mms.mongodb.com/help-hosted/current/tutorial/configure-application-high-availability/ describes the setting of the property, but does not explain why the property is needed.

      In the config file, we provide the following explanation:

      # IMPORTANT: MMS uses the client IP address for auditing and access control to
      # the API. When behind a load balancer your network security should not allow direct
      # access to the MMS web server. Failure to restrict access will allow clients to
      # potentially inject HTTP headers and spoof a client IP address.

      Please add this to the documentation as well.

      Attachments

        Activity

          People

            sam.kleinman Sam Kleinman (Inactive)
            cailin.nelson@mongodb.com Cailin Nelson
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:
              9 years, 17 weeks, 1 day ago