如何配置MongoDB通过Linux PAM实现用户密码认证?
Great question! Setting up MongoDB to authenticate users via Linux PAM is absolutely possible, though it’s true the official docs gloss over it in favor of LDAP. Let’s break this down step by step—you’ll need MongoDB Enterprise (since Community doesn’t support PAM auth) and a few configuration tweaks.
Prerequisites
- MongoDB Enterprise Edition: Community MongoDB doesn’t include the PAM authentication module. Verify your version with:
Look for "Enterprise" in the output to confirm you’re using the right build.mongod --version - A Linux system with PAM installed (standard on most distros like Ubuntu, RHEL, etc.).
Step 1: Create a PAM Service File for MongoDB
MongoDB needs a dedicated PAM service configuration to handle authentication. Create a file at /etc/pam.d/mongodb with the following content:
# MongoDB PAM authentication config auth required pam_unix.so account required pam_unix.so
This tells PAM to use the system’s standard Unix user database for both authentication (checking passwords) and account validation (ensuring the user account is active).
Note: You can customize this PAM config later (e.g., add MFA, restrict login times) by modifying this file with additional PAM modules.
Set the correct permissions for the file to avoid security issues:
sudo chmod 644 /etc/pam.d/mongodb sudo chown root:root /etc/pam.d/mongodb
Step 2: Update MongoDB Configuration
Edit your mongod.conf file (usually located at /etc/mongod.conf) to enable PAM authentication. Here’s the key section to add/modify:
security: authorization: enabled # Turn on role-based access control authenticationMechanisms: PLAIN # PAM uses the PLAIN auth mechanism pam: serviceName: mongodb # Matches the PAM service file we created earlier net: tls: mode: requireTLS # Critical! PLAIN sends passwords in plaintext, so TLS is mandatory certificateKeyFile: /path/to/your/server-cert-key.pem # Path to your TLS cert/key CAFile: /path/to/your/ca-cert.pem # Path to your CA cert
Critical: Never skip the TLS configuration. The PLAIN authentication mechanism transmits passwords as plaintext, so TLS ensures the connection is encrypted to prevent eavesdropping.
Restart MongoDB to apply the config changes:
sudo systemctl restart mongod
Step 3: Create MongoDB Users Linked to Linux Accounts
Now you need to create MongoDB user entries that map to existing Linux system users. These users will authenticate using their Linux passwords via PAM.
Connect to MongoDB with an admin user (or enable the localhost exception temporarily if you don’t have one):
mongosh --port 27017 --tls --tlsCAFile /path/to/your/ca-cert.pem
Switch to the admin database and create a user, using the external authentication source (this tells MongoDB to use PAM instead of its internal password store):
use admin db.createUser( { user: "jane_doe", // Must match an existing Linux system username roles: [ { role: "readWrite", db: "your_app_db" }, { role: "userAdminAnyDatabase", db: "admin" } // Example role, adjust as needed ], // Optional: Restrict the user to connect from specific IPs authenticationRestrictions: [ { clientSource: ["192.168.1.0/24"] } ] }, { w: "majority", wtimeout: 5000 } )
Step 4: Test the Authentication
Test logging in with the Linux user’s password to confirm everything works:
mongosh "mongodb://jane_doe@localhost:27017/your_app_db?authSource=external&authMechanism=PLAIN" \ --tls \ --tlsCAFile /path/to/your/ca-cert.pem
When prompted, enter the Linux password for jane_doe—you should be successfully authenticated and able to interact with the database.
Key Notes & Troubleshooting
- If MongoDB fails to start after updating the config, check the logs (
/var/log/mongodb/mongod.log) for errors related to PAM service file permissions or TLS config. - Ensure the MongoDB service user (usually
mongodb) has permission to access PAM system files—this is typically enabled by default on most distros. - If you need to modify a user’s password, just update their Linux system password (e.g., with
passwd jane_doe)—MongoDB will automatically use the new password on the next login, no need to update anything in MongoDB itself.
内容的提问来源于stack exchange,提问作者Gabriel Fair

