LAB M041: Authentication & Authorization (Application Delivery)
Authentication and authorization are two of the methods used by MongoDB to very that a user can be trusted to access data. MongoDB supports several mechanisms, and this lab will deep dive on how that trust is granted.
System access is always based on the simple principle that some people should have access to a system and others should not. Authentication and authorization are two parts of this principle in action. However, the simplicity quickly disappears as we dive into the details.
How, for example, can we know that a person attempting to access a system is who they claim to be? And what kinds of proof are needed before we can authenticate an identity? And to that end, how do we trust the proof that person presents? We quickly run into a problem. We cannot authenticate a person without proof. Furthermore, we cannot trust given proof unless the person providing it has been deemed trustworthy. It's circular.
We must collectively agree on something trustworthy, or the trust problem recurses forever. As system owners, we trust a central authority to authenticate that a person is who they claim to be.
Authentication and authorization are the mechanisms that provide that trust. MongoDB supports several mechanisms, and this lab will deep dive on how trust is granted through authentication and authorization.