Docs Menu

FIPS๋ฅผ ์œ„ํ•œ MongoDB ๊ตฌ์„ฑ

FIPS(์—ฐ๋ฐฉ ์ •๋ณด ์ฒ˜๋ฆฌ ํ‘œ์ค€)๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ์•”ํ˜ธํ™”ํ•˜๊ณ  ํ•ด๋…ํ•˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด ๋ชจ๋“ˆ ๋ฐ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์ธ์ฆํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋ฏธ๊ตญ ์ •๋ถ€์˜ ์ปดํ“จํ„ฐ ๋ณด์•ˆ ํ‘œ์ค€์ž…๋‹ˆ๋‹ค. MongoDB๋ฅผ OpenSSL์šฉ FIPS 140-2 ์ธ์ฆ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์™€ ํ•จ๊ป˜ ์‹คํ–‰๋˜๋„๋ก ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ์‹คํ–‰๋˜๊ฑฐ๋‚˜ ๋ช…๋ น์ค„์—์„œ ํ•„์š”์— ๋”ฐ๋ผ ์‹คํ–‰๋˜๋„๋ก FIPS๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

FIPS ๋ฐ TLS/SSL์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์„ค๋ช…์€ ์ด ๋ฌธ์„œ์˜ ๋ฒ”์œ„๋ฅผ ๋ฒ—์–ด๋‚ฉ๋‹ˆ๋‹ค. ์ด ํŠœํ† ๋ฆฌ์–ผ์€ FIPS ๋ฐ TLS/SSL์— ๋Œ€ํ•œ ์‚ฌ์ „ ์ง€์‹์ด ์žˆ๋‹ค๊ณ  ๊ฐ€์ •ํ•ฉ๋‹ˆ๋‹ค.

์ค‘์š”

MongoDB ๋ฐ FIPS

FIPS๋Š” ์•ก์„ธ์Šค ์ œ์–ด ์‹œ์Šคํ…œ์ด ์•„๋‹Œ ์•”ํ˜ธํ™” ์‹œ์Šคํ…œ์˜ ์†์„ฑ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์‚ฌ์šฉ ์ค‘์ธ ํ™˜๊ฒฝ์— FIPS ์ค€์ˆ˜ ์•”ํ˜ธํ™” ๋ฐ ์•ก์„ธ์Šค ์ œ์–ด๊ฐ€ ํ•„์š”ํ•œ ๊ฒฝ์šฐ, ์•ก์„ธ์Šค ์ œ์–ด ์‹œ์Šคํ…œ์ด FIPS ์ค€์ˆ˜ ์•”ํ˜ธํ™”๋งŒ ์‚ฌ์šฉํ•˜๋„๋ก ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

MongoDB์˜ FIPS ์ง€์› MongoDB ๋„คํŠธ์›Œํฌ ์•”ํ˜ธํ™”, SCRAM ์ธ์ฆ ๋ฐ X.509 ์ธ์ฆ ์— SSL/TLS ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ์‹์„ ๋‹ค๋ฃน๋‹ˆ๋‹ค. Kerberos ๋˜๋Š” LDAP ์ธ์ฆ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ด๋Ÿฌํ•œ ์™ธ๋ถ€ ๋ฉ”์ปค๋‹ˆ์ฆ˜์ด FIPS๋ฅผ ์ค€์ˆ˜ํ•˜๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ฐธ๊ณ 

MongoDB๋Š” TLS 1.1 ์ด์ƒ์ด ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์‹œ์Šคํ…œ์—์„œ TLS 1.0 ์•”ํ˜ธํ™”๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

FIPS ๋ชจ๋“œ ๋Š” MongoDB Enterprise ์—๋””์…˜์—์„œ๋งŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. MongoDB Enterprise ์„ค์น˜๋ฅผ ์ฐธ์กฐํ•˜์—ฌ MongoDB Enterprise ๋ฅผ ๋‹ค์šด๋กœ๋“œ ํ•˜๊ณ  ์„ค์น˜ MongoDB Enterprise.

FIPS ๋ชจ๋“œ๋Š” ๋‹ค์Œ ํ”Œ๋žซํผ์—์„œ ์ง€์›๋ฉ๋‹ˆ๋‹ค:

ํ”Œ๋žซํผ
TLS/SSL ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ

Linux

OpenSSL

Windows

๋ณด์•ˆ ์ฑ„๋„(Schannel)

macOS

๋ณด์•ˆ ์ „์†ก

MongoDB 6.0.7 ๋ถ€ํ„ฐ ์‹œ์ž‘๋ฉ๋‹ˆ๋‹ค. FIPS ๋ชจ๋“œ๋Š” OpenSSL3 ์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ์šด์˜ ์ฒด์ œ์˜ ๊ฒฝ์šฐ:

  • Ubuntu 22.04

  • RHEL 9

  • Amazon Linux 2023

Starting in MongoDB 8.0, FIPS ๋ชจ๋“œ ๋Š” Amazon Linux 2023.3 ์šฉ OpenSSL3 ๋ฅผ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

์•„๋ž˜์—์„œ ํ”Œ๋žซํผ์— ๋งž๋Š” ํƒญ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค:

MongoDB์˜ FIPS ๋ชจ๋“œ๋ฅผ ์ง€์›ํ•˜๋ ค๋ฉด Linux ์‹œ์Šคํ…œ์— FIPS 140-2 ๋ชจ๋“ˆ๋กœ ๊ตฌ์„ฑ๋œ OpenSSL ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๊ฐ€ ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜์—ฌ OpenSSL ์†Œํ”„ํŠธ์›จ์–ด์— FIPS ์ง€์›์ด ํฌํ•จ๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•˜์„ธ์š”.

    openssl version
  • Red Hat Enterprise Linux 6.x(RHEL 6.x) ๋˜๋Š” CentOS 6.x์™€ ๊ฐ™์€ ํŒŒ์ƒ ๋ฒ„์ „์˜ ๊ฒฝ์šฐ, FIPS ๋ชจ๋“œ ๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด OpenSSL ํˆดํ‚ท์˜ ๋ฒ„์ „์ด openssl-1.0.1e-16.el6_5 ์ด์ƒ์ด์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํ”Œ๋žซํผ์—์„œ OpenSSL ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์—…๊ทธ๋ ˆ์ด๋“œ ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ ํ•ฉ๋‹ˆ๋‹ค.

    sudo yum update openssl
  • ์ผ๋ถ€ Linux ๋ฒ„์ „์€ ์‚ฌ์ „ ํ• ๋‹น๋œ ์ฃผ์†Œ๋กœ ๋™์  ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์‚ฌ์ „ ์—ฐ๊ฒฐํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๋ฅผ ์ฃผ๊ธฐ์ ์œผ๋กœ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์ด ํ”„๋กœ์„ธ์Šค๋Š” OpenSSL ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ, ํŠนํžˆ libcrypto์„(๋ฅผ) ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค. ์ดํ›„ OpenSSL FIPS ๋ชจ๋“œ๋Š” ์‹œ์ž‘ ์‹œ ์ˆ˜ํ–‰๋œ ์„œ๋ช… ํ™•์ธ์— ์‹คํŒจํ•˜์—ฌ ์ปดํŒŒ์ผ ์ดํ›„ libcrypto์ด(๊ฐ€) ์ˆ˜์ •๋˜์ง€ ์•Š์•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

    Linux ์‚ฌ์ „ ๋งํฌ ํ”„๋กœ์„ธ์Šค๊ฐ€ libcrypto์„(๋ฅผ) ์‚ฌ์ „ ๋งํฌํ•˜์ง€ ์•Š๋„๋ก ๊ตฌ์„ฑํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo bash -c "echo '-b /usr/lib64/libcrypto.so.*' >>/etc/prelink.conf.d/openssl-prelink.conf"

FIPS ํ˜ธํ™˜ ์ž‘์—…์„ ์ง€์›ํ•˜๋„๋ก Linux ์‹œ์Šคํ…œ์„ ๊ตฌ์„ฑํ•œ ํ›„์—๋Š” ์•„๋ž˜ ๋‹จ๊ณ„์— ๋”ฐ๋ผ mongod ๋˜๋Š” mongos ์ธ์Šคํ„ด์Šค๊ฐ€ FIPS ๋ชจ๋“œ์—์„œ ์ž‘๋™ํ•˜๋„๋ก ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

TLS/SSL์„ ์‚ฌ์šฉํ•˜๋„๋ก ๋ฐฐํฌ์„œ๋ฒ„๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๊ด€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ TLS/SSL์„ ์œ„ํ•œ mongod ๋ฐ mongos ๊ตฌ์„ฑ์—์„œ ํ™•์ธํ•˜์„ธ์š”. ์ธ์ฆ์„œ๊ฐ€ FIPS๋ฅผ ์ค€์ˆ˜ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

TLS/SSL์„ ์œ„ํ•ด mongod ๋ฐ mongos ๊ตฌ์„ฑ ํ›„ ์ด ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

1

mongod ๋˜๋Š” mongos ์ธ์Šคํ„ด์Šค๊ฐ€ FIPS ๋ชจ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ตฌ์„ฑํ•˜๋ ค๋ฉด ์ธ์Šคํ„ด์Šค๋ฅผ ์ข…๋ฃŒํ•˜๊ณ  ๊ตฌ์„ฑ ํŒŒ์ผ์„ net.tls.FIPSMode ์„ค์ •์œผ๋กœ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

net:
tls:
FIPSMode: true
2

์˜ˆ๋ฅผ ๋“ค์–ด, ๊ตฌ์„ฑ ํŒŒ์ผ๋กœ mongod ์ธ์Šคํ„ด์Šค๋ฅผ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

mongod --config /etc/mongod.conf

์„œ๋ฒ„ ๋กœ๊ทธ ํŒŒ์ผ์—์„œ FIPS๊ฐ€ ํ™œ์„ฑํ™”๋˜์—ˆ๋‹ค๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

FIPS 140-2 mode activated

Microsoft ๋Š” Windows 10 ๋ฐ Windows Server 2016 ์ด์ƒ์˜ FIPS ๋ชจ๋“œ ๊ตฌ์„ฑ์— ๋Œ€ํ•œ ๋‹ค์Œ ๋ฆฌ์†Œ์Šค ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

Windows ์—์„œ FIPS 140- ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ2

FIPS ํ˜ธํ™˜ ์ž‘์—…์„ ์ง€์› ํ•˜๋„๋ก Windows ์‹œ์Šคํ…œ์„ ๊ตฌ์„ฑํ•œ ํ›„์—๋Š” ์•„๋ž˜ ๋‹จ๊ณ„์— ๋”ฐ๋ผ mongod ๋˜๋Š” mongos ์ธ์Šคํ„ด์Šค ๊ฐ€ FIPS ๋ชจ๋“œ ์—์„œ ์ž‘๋™ํ•˜๋„๋ก ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

TLS/SSL์„ ์‚ฌ์šฉํ•˜๋„๋ก ๋ฐฐํฌ์„œ๋ฒ„๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๊ด€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ TLS/SSL์„ ์œ„ํ•œ mongod ๋ฐ mongos ๊ตฌ์„ฑ์—์„œ ํ™•์ธํ•˜์„ธ์š”. ์ธ์ฆ์„œ๊ฐ€ FIPS๋ฅผ ์ค€์ˆ˜ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

TLS/SSL์„ ์œ„ํ•ด mongod ๋ฐ mongos ๊ตฌ์„ฑ ํ›„ ์ด ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

1

mongod ๋˜๋Š” mongos ์ธ์Šคํ„ด์Šค๊ฐ€ FIPS ๋ชจ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ตฌ์„ฑํ•˜๋ ค๋ฉด ์ธ์Šคํ„ด์Šค๋ฅผ ์ข…๋ฃŒํ•˜๊ณ  ๊ตฌ์„ฑ ํŒŒ์ผ์„ net.tls.FIPSMode ์„ค์ •์œผ๋กœ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

net:
tls:
FIPSMode: true
2

์˜ˆ๋ฅผ ๋“ค์–ด, ๊ตฌ์„ฑ ํŒŒ์ผ๋กœ mongod ์ธ์Šคํ„ด์Šค๋ฅผ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

mongod.exe --config /etc/mongod.conf

์„œ๋ฒ„ ๋กœ๊ทธ ํŒŒ์ผ์—์„œ FIPS๊ฐ€ ํ™œ์„ฑํ™”๋˜์—ˆ๋‹ค๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

FIPS 140-2 mode activated

์ง€์›๋˜๋Š” macOS ๋ฒ„์ „์€ ๊ธฐ๋ณธ๊ฐ’ FIPS๋ฅผ ์ค€์ˆ˜ํ•ฉ๋‹ˆ๋‹ค. ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ƒํƒœ๋ฅผ ํ™•์ธํ•˜๋ ค๋ฉด ์‚ฌ์šฉ ์ค‘์ธ macOS ๋ฒ„์ „์— ๋Œ€ํ•œ ์„ค๋ช…์„œ๋ฅผ ํ™•์ธํ•˜์„ธ์š”. ์˜ˆ๋ฅผ ์˜ˆ์‹œ Apple์€ macOS 10.14 ์— ๋Œ€ํ•ด ๋‹ค์Œ ๋ฆฌ์†Œ์Šค ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

โžค ์šฉ Apple FIPS ์•”ํ˜ธํ™” ๋ชจ๋“ˆ 10.14

ํ˜ธํ™˜๋˜๋Š” macOS ๋ฒ„์ „์—์„œ๋Š” ์•„๋ž˜ ๋‹จ๊ณ„์— ๋”ฐ๋ผ mongod ๋˜๋Š” mongos ์ธ์Šคํ„ด์Šค ๊ฐ€ FIPS ๋ชจ๋“œ ์—์„œ ์ž‘๋™ํ•˜๋„๋ก ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

TLS/SSL์„ ์‚ฌ์šฉํ•˜๋„๋ก ๋ฐฐํฌ์„œ๋ฒ„๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๊ด€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ TLS/SSL์„ ์œ„ํ•œ mongod ๋ฐ mongos ๊ตฌ์„ฑ์—์„œ ํ™•์ธํ•˜์„ธ์š”. ์ธ์ฆ์„œ๊ฐ€ FIPS๋ฅผ ์ค€์ˆ˜ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

TLS/SSL์„ ์œ„ํ•ด mongod ๋ฐ mongos ๊ตฌ์„ฑ ํ›„ ์ด ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

1

mongod ๋˜๋Š” mongos ์ธ์Šคํ„ด์Šค๊ฐ€ FIPS ๋ชจ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ตฌ์„ฑํ•˜๋ ค๋ฉด ์ธ์Šคํ„ด์Šค๋ฅผ ์ข…๋ฃŒํ•˜๊ณ  ๊ตฌ์„ฑ ํŒŒ์ผ์„ net.tls.FIPSMode ์„ค์ •์œผ๋กœ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

net:
tls:
FIPSMode: true
2

์˜ˆ๋ฅผ ๋“ค์–ด, ๊ตฌ์„ฑ ํŒŒ์ผ๋กœ mongod ์ธ์Šคํ„ด์Šค๋ฅผ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

mongod --config /etc/mongod.conf

์„œ๋ฒ„ ๋กœ๊ทธ ํŒŒ์ผ์—์„œ FIPS๊ฐ€ ํ™œ์„ฑํ™”๋˜์—ˆ๋‹ค๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

FIPS 140-2 mode activated

MongoDB 5.1 ๋ถ€ํ„ฐ FIPS ๋ชจ๋“œ ์—์„œ ์‹คํ–‰๋˜๋Š” ์ธ์Šคํ„ด์Šค๋Š” SCRAM-SHA-1 ์ธ์ฆ ๋ฉ”์ปค๋‹ˆ์ฆ˜ ์ด ๊ธฐ๋ณธ์ ์œผ๋กœ ๋น„ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. setParameter.authenticationMechanisms ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ SCRAM-SHA- ์ธ์ฆ ๋ฉ”์ปค๋‹ˆ์ฆ˜1 ์„ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ช…๋ น.

์ด ๋ณ€๊ฒฝ ์‚ฌํ•ญ์€ MongoDB setFeatureCompatibilityVersion๋ฅผ ๋Œ€์ƒ์œผ๋กœ ํ•˜๋Š” ๋“œ๋ผ์ด๋ฒ„์—๋Š” ์˜ํ–ฅ์„ ๋ฏธ์น˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. 4.0+.

SCRAM-SHA-1์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ:

  • MD5๋Š” ํ•„์š”ํ•˜์ง€๋งŒ ์•”ํ˜ธํ™” ๋ชฉ์ ์œผ๋กœ๋Š” ์‚ฌ์šฉ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  • FIPS ๋ชจ๋“œ ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ SCRAM-SHA-1 ๋Œ€์‹  ๋‹ค์Œ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

FIPS ๋ชจ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก mongod ๋ฐ mongos๋ฅผ ๊ตฌ์„ฑํ•œ ๊ฒฝ์šฐ, mongod ๋ฐ mongos๋Š” FIPS ํ˜ธํ™˜ ์—ฐ๊ฒฐ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ ํ”„๋กœ๊ทธ๋žจ์€ ๋” ์ด์ƒ --sslFIPSMode ์˜ต์…˜์„ ์ง€์›ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

FIPS ๋ชจ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก mongod ๋ฐ mongos ๋ฅผ ๊ตฌ์„ฑํ•˜๋ฉด ์ด์ „ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋„๊ตฌ๋Š” ์ž๋™์œผ๋กœ FIPS ํ˜ธํ™˜ ์—ฐ๊ฒฐ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ๋ณธ mongosh ๋ฐฐํฌ:

  • OpenSSL 3๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.

  • mongod ๋ฐ mongos๊ฐ€ FIPS ๋ชจ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ตฌ์„ฑํ•œ ๊ฒฝ์šฐ mongod ๋ฐ mongos์— ๋Œ€ํ•œ FIPS ํ˜ธํ™˜ ์—ฐ๊ฒฐ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

MongoDB๋Š” ๋‹ค์Œ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” MongoDB Shell ๋ฐฐํฌํŒ๋„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

  • ์„œ๋ฒ„์— ์„ค์น˜๋œ OpenSSL 1.1 ๋ฐ OpenSSL 3.

  • --tlsFIPSMode ์˜ต์…˜. mongosh FIPS ๋ชจ๋“œ๋ฅผ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ๋„ ์ฐธ์กฐํ•˜์„ธ์š”.