Authentication protects the door; TLS protects the wire. Without it every document and every SCRAM handshake crosses the network in a form a passive observer can record. Enable it with the server's certificate and key in one PEM file, the authority it trusts, and --tlsMode requireTLS.
mongod --port 28120 --dbpath tlsdata --tlsMode requireTLS \
--tlsCertificateKeyFile tls/mongod.pem --tlsCAFile tls/cert.pem \
--tlsAllowConnectionsWithoutCertificates
E="print('connected over TLS:', db.hello().ok === 1)"; CA=tls/cert.pem
mongosh "mongodb://localhost:28120/?directConnection=true" --eval "$E"
mongosh "mongodb://127.0.0.1:28120/?tls=true&tlsCAFile=$CA" --eval "$E"
mongosh "mongodb://localhost:28120/?tls=true&tlsCAFile=$CA" --eval "$E"MongoServerSelectionError: read ECONNRESET MongoServerSelectionError: Hostname/IP does not match certificate's altnames: IP: 127.0.0.1 is not in the cert's list: connected over TLS: true
The PEM is a self-signed certificate for CN=localhost serving as its own CA. ECONNRESET is what a plaintext client gets from a requireTLS server: the socket closes mid-handshake, so the error mentions nothing about TLS. The second failure is stricter than people expect — the client dialed 127.0.0.1, and a driver verifies that name against the certificate, so it is refused even though both point at the same machine; put every name and IP clients use into the subject alternative names. Two details more: MongoDB 8 1,815 refuses to start with --tlsMode but no CA, failing with InvalidOptions: The use of TLS without specifying a chain of trust is no longer supported, and once --tlsCAFile is set mongod expects client certificates too, which is why --tlsAllowConnectionsWithoutCertificates is needed here.
Network rules matter more than the certificate. net.bindIp defaults to 127.0.0.1, and bindIp: 0.0.0.0 is how databases end up on the public internet. Bind to the private interface and admit only the application subnet; on Atlas 1,815 , use the IP access list and private endpoints. Scanners find open MongoDB ports within hours. Encryption at rest is an Enterprise feature, so on Community you encrypt the volume instead; above it sits Queryable Encryption, from MongoDB 7.0, which encrypts chosen fields in the driver with keys the server never sees while equality and range queries on them still work.