• FAQ >
  • Security


How does Atlas encrypt my data?

Atlas uses whole volume (disk) encryption for any data at rest, including your cluster data and backups of that data.

Atlas also requires TLS encryption for client data and intra-cluster network communications.

If your organization requires more specific information regarding Atlas encryption, please contact Atlas MongoDB Support. From the Atlas project or cluster view, click Support in the left-hand navigation bar.

Can I disable TLS on my deployment?


What versions of TLS does Atlas support?

Atlas requires TLS connections for all Atlas clusters. After July 2020, Atlas will enable Transport Layer Security (TLS) protocol version 1.2 by default for all new Atlas clusters regardless of the MongoDB version.

MongoDB 4.0 and later disables support for TLS 1.0 where TLS 1.1+ is available. You can manually configure TLS 1.1 or 1.0 by editing your cluster configuration.

You can read more about timing and reasons for the change from the Payment Card Industry (PCI) as well as the National Institute of Standards and Technology (NIST).

If you have questions about TLS support or cannot update your applications to support TLS 1.2, please contact Atlas MongoDB Support.

To open a Atlas support ticket, log into the your Atlas account. Click the Support link in the Atlas console and fill in the requested details.

How do I know if my applications support TLS 1.2?

Applications whose underlying programming languages or security libraries predate TLS 1.2 may require updating to a more recent version to support TLS 1.2. You may also need to update the application host operating system to support TLS 1.2.

MongoDB and Atlas do not provide services to audit external applications for which versions of TLS support they support. Third party services such as may provide the appropriate tooling. MongoDB does not endorse the aforementioned service, and its reference is intended only as informational. Defer to your organization’s procedures in selecting the appropriate vendor or service for auditing your applications.

What do I have to do to update my clusters for TLS 1.2?

After auditing your applications for support of TLS 1.2 and updating any components of your technology stack that do not support TLS 1.2, you must manually modify your cluster configuration to use TLS 1.2.

Can I force enable TLS 1.0?

Atlas allows users to manually configure TLS 1.0 during cluster modification.

Enabling TLS 1.0 for any Atlas cluster carries significant risks. Consider enabling TLS 1.0 only for as long as required to update your application stack to support TLS 1.2.

Which certificate authority signs MongoDB Atlas cluster TLS certificates?

The MongoDB Atlas TLS certificate changed on 25 February 2020.

MongoDB Atlas moved to Let’s Encrypt as the new Certificate Authority for TLS certificates for all Atlas clusters.

All newly created M10+ Atlas clusters already utilize the new certificates and can be used to test connectivity.

Please review the following scenarios to ensure that you will not experience connectivity issues:

Hard-coded Certificate Authority

If you hard-coded the DigiCert root Certificate Authority as the only trusted Certificate Authority utilized for your application’s connection to Atlas, please ensure that you add the Let’s Encrypt root Certificate Authoritys to your certificate store. Add both of the following root Certificate Authoritys for Let’s Encrypt:

Java Users

Let’s Encrypt isn’t present in the default trust store for Java version 7 prior to the 7u111 update, or Java version 8 prior to the 8u101 update. Use a Java release after 19 July 2016.

Please ensure your Java client software is up-to-date. The latest Java versions are strongly recommended for many improvements beyond these new Certificate Authority requirements for our TLS certificates.

If you have your own trust store, add the Let’s Encrypt certificate to it. To learn more, see Hard-coded Certificate Authority.

Everyone Else

This change shouldn’t impact you if you use a recent programming language and operating system version.

←   Networking Storage  →