


How to configure the paths of ssl_key, ssl-cert and ssl-ca in mysql and examples of establishing ssl connections
1. Create CA private key and CA certificate
(1) Download and install openssl, configure the bin directory to environment variables;
(2) Set the openssl.cfg path (if If not set, an error will be reported and the openssl configuration file cannot be found)
set OPENSSL_CONF=G:\Program Files\openssl\openssl-1.0.2d-fips-2.0.10\bin\openssl.cnf
(3) Generate a CA private key (extra file: ca-key.pem)
openssl genrsa 2048 > ca-key.pem
(4) Generate a digital certificate through the CA private key (when executing this command, you will need to fill in some questions, just fill them in casually, such as: CN , KunMing, KunMing, KunMing, kmddkj, kmddkj, kmddkj, 786479786@qq.com; two extra files: ca-cert.pem)
openssl req -sha1 -new -x509 -nodes -days 3650 -key ca-key.pem > ca-cert.pem
2. Create the server-side RSA private key and digital certificate
(1) Create the server-side private key and a certificate request file (you need to answer a few questions, just fill them in casually. But you need to pay attention to Yes, A challenge password and An optional company name need to be empty; additional files: server-key.pem server-req.pem)
openssl req -sha1 -newkey rsa:2048 -days 3650 -nodes -keyout server-key.pem > server-req.pem
(2 ) Convert the generated private key to the RSA private key file format
openssl rsa -in server-key.pem -out server-key.pem
(3) Use the originally generated CA certificate to generate a server-side digital certificate (extra files: server-cert.pem)
openssl x509 -sha1 -req -in server-req.pem -days 3650 -CA ca-cert.pem -CAkey ca-key.pem -set_serial 01 -out server-cert.pem
3. Create the client’s RSA private key and digital certificate
(1) for the client The client generates a private key and certificate request file (extra files: client-key.pem client-req.pem)
openssl req -sha1 -newkey rsa:2048 -days 3650 -nodes -keyout client-key.pem > client-req.pem
(2) Convert the generated private key For the RSA private key file format
openssl rsa -in client-key.pem -out client-key.pem
(3) Create a digital certificate for the client (extra file: client-cert.pem)
openssl x509 -sha1 -req -in client-req.pem -days 3650 -CA ca-cert.pem -CAkey ca-key.pem -set_serial 01 -out client-cert.pem
SSL configuration and generated file description:In the previous steps, we have generated 8 files, namely:
ca-cert.pem: CA certificate, used to generate server/client digital certificates.
ca-key.pem: CA private key, used to generate server/client digital certificates.
server-key.pem: Server-side RSA private key
server-req.pem: Server-side certificate request file, used to generate server-side digital certificates.
server-cert .pem: Server-side digital certificate.
client-key.pem: Client's RSA private key
client-req.pem: Client's certificate request file, used to generate the client's digital certificate .
client-cert.pem: Client’s digital certificate.
4. Server-side configuration
The server-side needs to use three files, They are: CA certificate, server-side RSA private key, server-side digital certificate, we need to add the following content under the [mysqld] configuration domain:
#[mysqld]下加入如下代码: ssl-ca=G:/ProgramData/MySQL/MySQL Server 5.6/mykey/ca-cert.pem ssl-cert=G:/ProgramData/MySQL/MySQL Server 5.6/mykey/server-cert.pem ssl-key=G:/ProgramData/MySQL/MySQL Server 5.6/mykey/server-key.pem
5. After the configuration is complete, we need to restart the MySQL service to make the configuration take effect.
6. After the configuration is complete, use root to log in to MySQL and execute show variables like '%ssl%'; the test is successful.
show variables like '%ssl%';
The above is the detailed content of How to configure the paths of ssl_key, ssl-cert and ssl-ca in mysql and examples of establishing ssl connections. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics



MySQL is an open source relational database management system. 1) Create database and tables: Use the CREATEDATABASE and CREATETABLE commands. 2) Basic operations: INSERT, UPDATE, DELETE and SELECT. 3) Advanced operations: JOIN, subquery and transaction processing. 4) Debugging skills: Check syntax, data type and permissions. 5) Optimization suggestions: Use indexes, avoid SELECT* and use transactions.

You can open phpMyAdmin through the following steps: 1. Log in to the website control panel; 2. Find and click the phpMyAdmin icon; 3. Enter MySQL credentials; 4. Click "Login".

MySQL is an open source relational database management system, mainly used to store and retrieve data quickly and reliably. Its working principle includes client requests, query resolution, execution of queries and return results. Examples of usage include creating tables, inserting and querying data, and advanced features such as JOIN operations. Common errors involve SQL syntax, data types, and permissions, and optimization suggestions include the use of indexes, optimized queries, and partitioning of tables.

Redis uses a single threaded architecture to provide high performance, simplicity, and consistency. It utilizes I/O multiplexing, event loops, non-blocking I/O, and shared memory to improve concurrency, but with limitations of concurrency limitations, single point of failure, and unsuitable for write-intensive workloads.

MySQL is chosen for its performance, reliability, ease of use, and community support. 1.MySQL provides efficient data storage and retrieval functions, supporting multiple data types and advanced query operations. 2. Adopt client-server architecture and multiple storage engines to support transaction and query optimization. 3. Easy to use, supports a variety of operating systems and programming languages. 4. Have strong community support and provide rich resources and solutions.

MySQL's position in databases and programming is very important. It is an open source relational database management system that is widely used in various application scenarios. 1) MySQL provides efficient data storage, organization and retrieval functions, supporting Web, mobile and enterprise-level systems. 2) It uses a client-server architecture, supports multiple storage engines and index optimization. 3) Basic usages include creating tables and inserting data, and advanced usages involve multi-table JOINs and complex queries. 4) Frequently asked questions such as SQL syntax errors and performance issues can be debugged through the EXPLAIN command and slow query log. 5) Performance optimization methods include rational use of indexes, optimized query and use of caches. Best practices include using transactions and PreparedStatemen

MySQL and SQL are essential skills for developers. 1.MySQL is an open source relational database management system, and SQL is the standard language used to manage and operate databases. 2.MySQL supports multiple storage engines through efficient data storage and retrieval functions, and SQL completes complex data operations through simple statements. 3. Examples of usage include basic queries and advanced queries, such as filtering and sorting by condition. 4. Common errors include syntax errors and performance issues, which can be optimized by checking SQL statements and using EXPLAIN commands. 5. Performance optimization techniques include using indexes, avoiding full table scanning, optimizing JOIN operations and improving code readability.

Effective monitoring of Redis databases is critical to maintaining optimal performance, identifying potential bottlenecks, and ensuring overall system reliability. Redis Exporter Service is a powerful utility designed to monitor Redis databases using Prometheus. This tutorial will guide you through the complete setup and configuration of Redis Exporter Service, ensuring you seamlessly build monitoring solutions. By studying this tutorial, you will achieve fully operational monitoring settings
