On this page
Self-managed X.509 certificates provide database users access to the database deployments in their project. Database users are separate from Atlas users. Database users have access to MongoDB databases, while Atlas users have access to the Atlas application itself.
In order to use self-managed X.509 certificates, you must have a Public Key Infrastructure to integrate with MongoDB Atlas.
You can provide a Certificate Authority (CA) by:
- Clicking Upload and selecting a
.pemfile from your filesystem.
- Copying the contents of a
.pemfile into the provided text area.
You can concatenate multiple CAs in the same
.pem file or in the
text area. Users can authenticate with certificates generated by any
of the provided CAs.
When you upload a CA, a project-level alert is automatically created to send a notification 30 days before the CA expires, repeating every 24 hours. You can view and edit this alert from Atlas's Alert Settings page. For more information on configuring alerts, see Configure Alert Settings.
To edit your CA once uploaded, click the Self-Managed X.509 Authentication Settings icon.
The user's Common Name (CN) protected by the TLS/SSL certificate. For more information, see RFC 2253.
If your common name is "Jane Doe", your organization is "MongoDB", and your country is "US", insert the following into the Common Name field:
You can assign roles in one of the following ways:
For information on the built-in Atlas privileges, see Built-in Roles.