Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was hoping the security enhancements would include SSL certificate validation. Anyone know why they don't do that, or how a user should approach that limitation?


We'll be moving away from MongoDB because it doesn't support certificate validation. What is the point of SSL connections if you don't validate the certificate? It seems that you get all the drawbacks of encryption (overhead, throughput) with none of the benefits (security).

I'd love to see a solution.



Have you considered SSL tunneling?


SSL certificate validation is in the 2.4 release.


I'm guessing this is the ticket for SSL support https://jira.mongodb.org/browse/SERVER-7202




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: