- MongoDB Agent >
- Configure the MongoDB Agent for Access Control >
- Configure MongoDB Agent for Authentication
Configure MongoDB Agent for Authentication¶
MongoDB supports the following authentication mechanisms depending on your MongoDB version:
MongoDB Version | Default Authentication Mechanism |
---|---|
4.0 or later | SCRAM authentication
mechanisms with the SHA-256 and SHA-1 hash functions.
SCRAM-SHA-1 (RFC 5802) and SCRAM-SHA-256
(RFC 7677) are IETF standards that define best
practice methods for implementation of challenge-response
mechanisms for authenticating users with passwords. |
3.0 to 3.6 | SCRAM authentication mechanism with``SHA-1`` hash function. |
2.6 or earlier | MongoDB Challenge and Response (MONGODB-CR ). MONGODB-CR
is a challenge-response mechanism that authenticates users
through passwords. |
Prerequisites¶
Configure Deployments to Use Authentication¶
The MongoDB Agent interacts with the MongoDB databases in your deployment as a MongoDB user would. As a result, you must configure your MongoDB deployment and the MongoDB Agent to support authentication.
You can specify the deployment’s authentication mechanisms when adding the deployment, or you can edit the settings for an existing deployment. At minimum, the deployment must enable the authentication mechanism you want the MongoDB Agent to use. The MongoDB Agent can use any supported authentication mechanism.
Configure the MongoDB Agent for Authentication¶
The MongoDB Agent can use SCRAM-SHA-1
or SCRAM-SHA-256
to authenticate to hosts that enforce access control.
Note
With Automation, Ops Manager manages MongoDB Agent authentication for you. To learn more about authentication, see Enable Username and Password Authentication for your Ops Manager Project.
- Deployments Managed by Automation
- Deployments Not Managed by Automation
When you install the MongoDB Agent with Automation, Ops Manager creates a
user to authenticate on the MongoDB database. Ops Manager create this
MongoDB user (mms-automation
) in the admin
database with
the correct privileges for each MongoDB Agent function.
Configure these credentials in Ops Manager.
- Navigate to Deployment arrow right icon Security arrow right icon Edit Settings arrow right icon Edit Credentials.
- Continue through the modal until you see the Configure Ops Manager Agents page
Add the appropriate credentials:
Setting Value MongoDB Agent Username Enter the MongoDB Agent username. MongoDB Agent Password Enter the password for the MongoDB Agent username.