[SERVER-28229] Bind to localhost by default Created: 07/Mar/17 Updated: 09/Mar/18 Resolved: 28/Apr/17 |
|
| Status: | Closed |
| Project: | Core Server |
| Component/s: | Networking |
| Affects Version/s: | None |
| Fix Version/s: | 3.5.7 |
| Type: | Improvement | Priority: | Major - P3 |
| Reporter: | Spencer Jackson | Assignee: | Spencer Jackson |
| Resolution: | Done | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Issue Links: |
|
||||||||||||||||||||||||
| Backwards Compatibility: | Major Change | ||||||||||||||||||||||||
| Sprint: | Platforms 2017-04-17, Platforms 2017-05-08 | ||||||||||||||||||||||||
| Participants: | |||||||||||||||||||||||||
| Linked BF Score: | 0 | ||||||||||||||||||||||||
| Description |
|
User Summary as of May 17, 2017 MongoDB 3.5.7 introduces a new line of protection from unauthorized access: as of this release, MongoDB servers will only listen for connections on the local host unless explicitly configured to listen on another address. The next production release, 3.6, incorporates this change. Before changing this new default behavior, users are encouraged to review our Security Checklist. To make MongoDB servers accept connections from remote and local sources, either:
or
When MongoDB is only listening for connections on the local host, remote clients will be unable to connect. Connection attempts from remote clients may see error messages such as "Connection refused". If your MongoDB servers need to accept external network connections, please go through our Security Checklist before following the instructions above. Original descriptionMongoDB binaries should bind to localhost by default. This will allow small deployments and testing environments to be used from localhost, while not being accessible from the internet. The following changes shall be made: |
| Comments |
| Comment by Githook User [ 28/Apr/17 ] |
|
Author: {u'username': u'spencerjackson', u'name': u'Spencer Jackson', u'email': u'spencer.jackson@mongodb.com'}Message: |
| Comment by Githook User [ 25/Apr/17 ] |
|
Author: {u'username': u'kaloianm', u'name': u'Kaloian Manassiev', u'email': u'kaloian.manassiev@mongodb.com'}Message: Revert " This reverts commit d6b244fce44e6729485b1521346db6e372f6b901. |
| Comment by Githook User [ 24/Apr/17 ] |
|
Author: {u'username': u'spencerjackson', u'name': u'Spencer Jackson', u'email': u'spencer.jackson@mongodb.com'}Message: |