Re: MongoDB Security Defaults

2015-02-16 Thread Ryan S. Brown
On 02/16/2015 06:56 AM, Marek Skalický wrote: Hello, this change was in version 2.6.6-4. I were cleaning config files, adding new options,... I didn't want to change any default configuration. Ah, makes sense. That mongod documentation is ripe for misinterpretation. So bind_ip change

MongoDB Security Defaults

2015-02-13 Thread Ryan S. Brown
Hello, After reading this article[1] on how many totally unsecured mongodb installations there are on the internet, I noticed a recent (and worrying) change in the defaults on Fedora's mongodb package. In January, the Fedora rawhide package for mongo[2] was changed to listen on all interfaces by

Re: MongoDB Security Defaults

2015-02-13 Thread Ryan S. Brown
On 02/13/2015 11:25 AM, Frank Ch. Eigler wrote: Ryan S. Brown rya...@redhat.com writes: [...] In January, the Fedora rawhide package for mongo[2] was changed to listen on all interfaces by default [...] To help protect users, I think the default should be changed back to localhost only.

Re: MongoDB Security Defaults

2015-02-13 Thread drago01
On Fri, Feb 13, 2015 at 11:37 PM, Ryan S. Brown rya...@redhat.com wrote: On 02/13/2015 11:25 AM, Frank Ch. Eigler wrote: Ryan S. Brown rya...@redhat.com writes: [...] In January, the Fedora rawhide package for mongo[2] was changed to listen on all interfaces by default [...] To help