[SERVER-21746] system.user collection auditing issues Created: 02/Dec/15 Updated: 17/Jul/18 Resolved: 17/Jul/18 |
|
| Status: | Closed |
| Project: | Core Server |
| Component/s: | Security |
| Affects Version/s: | 2.6.5 |
| Fix Version/s: | None |
| Type: | Bug | Priority: | Critical - P2 |
| Reporter: | Jonathan Abrahams | Assignee: | DO NOT USE - Backlog - Platform Team |
| Resolution: | Done | Votes: | 0 |
| Labels: | audit | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Issue Links: |
|
||||||||
| Operating System: | ALL | ||||||||
| Participants: | |||||||||
| Description |
|
User management commands are all audited except if the system.users collection is directly modified. |
| Comments |
| Comment by Spencer Jackson [ 17/Jul/18 ] |
|
Modifications to collections can be audited as of 2.6.5, using the CRUD auditing capabilities provided by https://docs.mongodb.com/manual/reference/parameters/#param.auditAuthorizationSuccess. |