SOP For Setting Up SSL in MySQL
SOP For Setting Up SSL in MySQL
• Encryption at rest – usually done via TDE or equivalent - Have Finished this one
too
• Encryption in transit – TLS v1.2 ==> Use my SOP for Setting up SSL In MySQL
• Access management – via AGS
• Logging – there’s a nice tool called Database Access Manager (DAM) by McAfee. I
believe we have an enterprise license for it
openssl req -new -x509 -nodes -days 3660 -key ca-key.pem -out ca.pem
openssl req -newkey rsa:2048 -days 3660 -nodes -keyout mysql-server-key.pem -out
mysql-server-req.pem
openssl x509 -req -in mysql-server-req.pem -days 3660 -CA ca.pem -CAkey ca-key.pem
-set_serial 01 -out mysql-server-cert.pem
openssl req -newkey rsa:2048 -days 3660 -nodes -keyout mysql-client-key.pem -out
mysql-client-req.pem
openssl x509 -req -in mysql-client-req.pem -days 3660 -CA ca.pem -CAkey ca-key.pem
-set_serial 01 -out mysql-client-cert.pem
ssl-ca=/etc/ssl/mysql/ca.pem
ssl-cert=/etc/ssl/mysql/mysql-client-cert.pem
ssl-key=/etc/ssl/mysql/mysql-client-key.pem
[mysqld]
ssl-ca=/etc/ssl/mysql/ca.pem
ssl-cert=/etc/ssl/mysql/mysql-server-cert.pem
ssl-key=/etc/ssl/mysql/mysql-server-key.pem
#!/bin/sh
##Create a directory that will house all your keys for mysql
##/etc/ssl/mysql
cd /etc/ssl/
mkdir mysql
cd mysql/
echo "====\nCreating the CA certificate\n===="
-subj
"/C=US/ST=Florida/L=Clearwater/O=Clarity.net/OU=Hotfix/CN=tpahotdb.clarity.net/emai
[email protected]" \
-subj
"/C=US/ST=Florida/L=Clearwater/O=Clarity.net/OU=Hotfix/CN=tpahotdb/emailAddress=sef
[email protected]" \
openssl x509 -req -in mysql-server-req.pem -days 3660 -CA ca.pem -CAkey ca-key.pem
-set_serial 01 -out mysql-server-cert.pem
do
-subj
"/C=US/ST=Florida/L=Clearwater/O=Clarity/OU=Hotfix/CN=tpahotdb/emailAddress=sefange
@clarityservices.com" \
done
cd ..
#!/bin/sh
##Create a directory that will house all your keys for mysql
##/etc/ssl/mysql
cd /etc/ssl/
mkdir mysql
cd mysql/
echo "====\nCreating the CA certificate\n===="
-subj
"/C=US/ST=Florida/L=Clearwater/O=Clarity.net/OU=Hotfix/CN=tpahotdb.clarity.net/emai
[email protected]" \
-subj
"/C=US/ST=Florida/L=Clearwater/O=Clarity.net/OU=Hotfix/CN=tpahotdb/emailAddress=sef
[email protected]" \
openssl x509 -req -in mysql-server-req.pem -days 3660 -CA ca-cert.pem -CAkey ca-
key.pem -set_serial 01 -out mysql-server-cert.pem
do
-subj
"/C=US/ST=Florida/L=Clearwater/O=Clarity/OU=Hotfix/CN=tpahotdb/emailAddress=sefange
@clarityservices.com" \
done
cd ..