{"id":4559,"date":"2021-06-30T02:35:02","date_gmt":"2021-06-29T17:35:02","guid":{"rendered":"https:\/\/lain.dnsalias.org\/~garry\/blog\/?p=4559"},"modified":"2021-06-30T02:37:34","modified_gmt":"2021-06-29T17:37:34","slug":"mysql%e3%81%aessl%e9%80%9a%e4%bf%a1","status":"publish","type":"post","link":"https:\/\/lain.dnsalias.org\/~garry\/blog\/?p=4559","title":{"rendered":"mysql\u306eSSL\u901a\u4fe1"},"content":{"rendered":"<p>mysql8.0\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u30ec\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u884c\u3063\u3066\u3044\u305f\u306e\u3060\u304c<\/p>\n<p>\u518d\u8d77\u52d5\u3059\u308b\u305f\u3073\u306b\u3001\u624b\u52d5\u3067\u63a5\u7d9a\u3057\u306a\u3051\u308c\u3070\u306a\u3089\u306a\u3044\u306e\u3067\u3001<\/p>\n<p>SSL\u901a\u4fe1\u306b\u3057\u3066\u307f\u305f\u3002<\/p>\n<p>\u691c\u7d22\u3067\u3044\u308d\u3044\u308d\u30b0\u30b0\u3063\u3066\u307f\u305f\u304c\u3001\u7d50\u5c40\u306e\u3068\u3053\u308d\u521d\u3081\u304b\u3089\u8a2d\u5b9a\u3084\u8a3c\u660e\u66f8\u306a\u3069\u306f\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u305f\u306e\u3067<\/p>\n<p>CHANGE MASTER TO<\/p>\n<p>MASTER_SSL      = 1;\n<\/p>\n<p>\u3068\u3059\u308b\u3060\u3051\u3067\u52d5\u4f5c\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u30de\u30b9\u30bf\u30fc\u5074\u306e\u8a3c\u660e\u66f8\u3068\u304b\u3092\u30b9\u30ec\u30fc\u30d6\u5074\u306b\u30b3\u30d4\u30fc\u3057\u3066\u3001\u305d\u308c\u3092\u30b9\u30ec\u30fc\u30d6\u306b\u8a2d\u5b9a\u3059\u308b\u8a18\u8f09\u304c<\/p>\n<p>\u7d50\u69cb\u898b\u53d7\u3051\u3089\u308c\u307e\u3057\u305f\u304c\u3001\u4e0a\u8a18\u3060\u3051\u3067\u52d5\u4f5c\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u5404\u3005\u306eSSL\u8a2d\u5b9a\u306f\u521d\u671f\u8a2d\u5b9a\u306b\u542b\u307e\u308c\u3066\u3044\u305f\u3088\u3046\u3067<\/p>\n<p>show global variables like &#8216;%ssl%&#8217;;<\/p>\n<p>\n+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-+&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;+<\/p>\n<p>\n| Variable_name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Value&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-+&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;+<\/p>\n<p>\n| have_openssl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | YES&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| have_ssl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | YES&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| performance_schema_show_processlist | OFF&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| ssl_ca&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | ca.pem&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| ssl_capath&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| ssl_cert&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | server-cert.pem |<\/p>\n<p>\n| ssl_cipher&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| ssl_crl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| ssl_crlpath&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| ssl_fips_mode&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | OFF&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<\/p>\n<p>\n| ssl_key&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | server-key.pem&nbsp; |<\/p>\n<p>\n+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-+&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;+<\/p>\n<p>SSL\u95a2\u4fc2\u306f\u3053\u3093\u306a\u611f\u3058\u304c\u521d\u3081\u304b\u3089\u5165\u3063\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u8a3c\u660e\u66f8\u81ea\u4f53\u306f\u3001\/var\/db\/mysql\u306e\u4e2d\u306b\u4f5c\u6210\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>mysql8.0\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u30ec\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u884c\u3063\u3066\u3044\u305f\u306e\u3060\u304c \u518d\u8d77\u52d5\u3059\u308b &hellip; <a href=\"https:\/\/lain.dnsalias.org\/~garry\/blog\/?p=4559\">\u7d9a\u304d\u3092\u8aad\u3080 <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"class_list":["post-4559","post","type-post","status-publish","format-standard","hentry","category-freebsd"],"_links":{"self":[{"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=\/wp\/v2\/posts\/4559","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4559"}],"version-history":[{"count":2,"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=\/wp\/v2\/posts\/4559\/revisions"}],"predecessor-version":[{"id":4561,"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=\/wp\/v2\/posts\/4559\/revisions\/4561"}],"wp:attachment":[{"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4559"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lain.dnsalias.org\/~garry\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}