You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置MongoDB通过Linux PAM实现用户密码认证?

How to Configure MongoDB for Linux PAM Authentication

Great question! Setting up MongoDB to authenticate users via Linux PAM is absolutely possible, though it’s true the official docs gloss over it in favor of LDAP. Let’s break this down step by step—you’ll need MongoDB Enterprise (since Community doesn’t support PAM auth) and a few configuration tweaks.

Prerequisites

  • MongoDB Enterprise Edition: Community MongoDB doesn’t include the PAM authentication module. Verify your version with:
    mongod --version
    
    Look for "Enterprise" in the output to confirm you’re using the right build.
  • A Linux system with PAM installed (standard on most distros like Ubuntu, RHEL, etc.).

Step 1: Create a PAM Service File for MongoDB

MongoDB needs a dedicated PAM service configuration to handle authentication. Create a file at /etc/pam.d/mongodb with the following content:

# MongoDB PAM authentication config
auth    required    pam_unix.so
account required    pam_unix.so

This tells PAM to use the system’s standard Unix user database for both authentication (checking passwords) and account validation (ensuring the user account is active).

Note: You can customize this PAM config later (e.g., add MFA, restrict login times) by modifying this file with additional PAM modules.

Set the correct permissions for the file to avoid security issues:

sudo chmod 644 /etc/pam.d/mongodb
sudo chown root:root /etc/pam.d/mongodb

Step 2: Update MongoDB Configuration

Edit your mongod.conf file (usually located at /etc/mongod.conf) to enable PAM authentication. Here’s the key section to add/modify:

security:
  authorization: enabled  # Turn on role-based access control
  authenticationMechanisms: PLAIN  # PAM uses the PLAIN auth mechanism
  pam:
    serviceName: mongodb  # Matches the PAM service file we created earlier
net:
  tls:
    mode: requireTLS  # Critical! PLAIN sends passwords in plaintext, so TLS is mandatory
    certificateKeyFile: /path/to/your/server-cert-key.pem  # Path to your TLS cert/key
    CAFile: /path/to/your/ca-cert.pem  # Path to your CA cert

Critical: Never skip the TLS configuration. The PLAIN authentication mechanism transmits passwords as plaintext, so TLS ensures the connection is encrypted to prevent eavesdropping.

Restart MongoDB to apply the config changes:

sudo systemctl restart mongod

Step 3: Create MongoDB Users Linked to Linux Accounts

Now you need to create MongoDB user entries that map to existing Linux system users. These users will authenticate using their Linux passwords via PAM.

Connect to MongoDB with an admin user (or enable the localhost exception temporarily if you don’t have one):

mongosh --port 27017 --tls --tlsCAFile /path/to/your/ca-cert.pem

Switch to the admin database and create a user, using the external authentication source (this tells MongoDB to use PAM instead of its internal password store):

use admin
db.createUser(
  {
    user: "jane_doe",  // Must match an existing Linux system username
    roles: [
      { role: "readWrite", db: "your_app_db" },
      { role: "userAdminAnyDatabase", db: "admin" }  // Example role, adjust as needed
    ],
    // Optional: Restrict the user to connect from specific IPs
    authenticationRestrictions: [ { clientSource: ["192.168.1.0/24"] } ]
  },
  { w: "majority", wtimeout: 5000 }
)

Step 4: Test the Authentication

Test logging in with the Linux user’s password to confirm everything works:

mongosh "mongodb://jane_doe@localhost:27017/your_app_db?authSource=external&authMechanism=PLAIN" \
  --tls \
  --tlsCAFile /path/to/your/ca-cert.pem

When prompted, enter the Linux password for jane_doe—you should be successfully authenticated and able to interact with the database.

Key Notes & Troubleshooting

  • If MongoDB fails to start after updating the config, check the logs (/var/log/mongodb/mongod.log) for errors related to PAM service file permissions or TLS config.
  • Ensure the MongoDB service user (usually mongodb) has permission to access PAM system files—this is typically enabled by default on most distros.
  • If you need to modify a user’s password, just update their Linux system password (e.g., with passwd jane_doe)—MongoDB will automatically use the new password on the next login, no need to update anything in MongoDB itself.

内容的提问来源于stack exchange,提问作者Gabriel Fair

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:53:05