Uploaded image for project: 'Documentation'
  1. Documentation
  2. DOCS-4210

Clarify use of mms.remoteIp.header property

      This page https://mms.mongodb.com/help-hosted/current/tutorial/configure-application-high-availability/ describes the setting of the property, but does not explain why the property is needed.

      In the config file, we provide the following explanation:

      # IMPORTANT: MMS uses the client IP address for auditing and access control to
      # the API. When behind a load balancer your network security should not allow direct
      # access to the MMS web server. Failure to restrict access will allow clients to
      # potentially inject HTTP headers and spoof a client IP address.
      

      Please add this to the documentation as well.

            Assignee:
            sam.kleinman Sam Kleinman (Inactive)
            Reporter:
            cailin.nelson@mongodb.com Cailin Nelson
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved:
              9 years, 28 weeks, 1 day ago