Type:
New Feature
Priority:
Major
Resolution:
Unresolved
Fix Version/s:
None
mariadb ssl_rsa_setup maintenance tool with galera option would accelerate tls deployment on galera cluster
mariadb is supporting tls encryption in client - server channels
as well in mariadb galera cluster.
Deployment of ssl however requires more steps and it would be useful to have
mariadb_ssl_rsa_setup tool to accelerate it and avoid miss configuration errors.
tool may generate client and server certification files and keys
export them optionally to the server or cluster nodes /etc/mysql/certification dir(s)
with appropriate ownership and permissions
and prepare optionally server or cluster nodes configuration files .
[root@t4w5 ~]# ls -l /etc/ | grep mysql
drwxr-xr-x 3 mysql mysql 16 May 11 13:51 mysql
[root@t4w5 ~]# ls /etc/mysql/cc
client.crt client.key client.pem server.crt server.key server.pem
galera node server.cnf
[mysqld]
#ssl-ca=/etc/mysql/cc/server.crt
#ssl-key=/etc/mysql/cc/server.key
#ssl-cert=/etc/mysql/cc/server.pem
[client]
#ssl-ca=/etc/mysql/cc/client.crt
#ssl-key=/etc/mysql/cc/client.key
#ssl-cert=/etc/mysql/cc/client.pem
[mysqld]
ssl-ca=/etc/mysql/cc/server.crt
ssl-key=/etc/mysql/cc/server.key
ssl-cert=/etc/mysql/cc/server.pem
[client]
ssl-ca=/etc/mysql/cc/client.crt
ssl-key=/etc/mysql/cc/client.key
ssl-cert=/etc/mysql/cc/client.pem
relates to
MDEV-15568
SST + SSL/TLS broken due to socat CN check
Closed
links to
{"report":{"fcp":776.2999999523163,"ttfb":152,"pageVisibility":"visible","entityId":67639,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"8393d337-dc5a-43af-b5d6-b30c9140f1c6","navigationType":0,"readyForUser":838.5999999046326,"redirectCount":0,"resourceLoadedEnd":1100.2000000476837,"resourceLoadedStart":178.5,"resourceTiming":[{"duration":163.89999985694885,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":178.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":178.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":342.39999985694885,"responseStart":0,"secureConnectionStart":0},{"duration":163.59999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":178.79999995231628,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":178.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":342.39999985694885,"responseStart":0,"secureConnectionStart":0},{"duration":172.79999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":179,"connectEnd":179,"connectStart":179,"domainLookupEnd":179,"domainLookupStart":179,"fetchStart":179,"redirectEnd":0,"redirectStart":0,"requestStart":179,"responseEnd":351.7999999523163,"responseStart":351.7999999523163,"secureConnectionStart":179},{"duration":217.60000014305115,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":179.09999990463257,"connectEnd":179.09999990463257,"connectStart":179.09999990463257,"domainLookupEnd":179.09999990463257,"domainLookupStart":179.09999990463257,"fetchStart":179.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":179.09999990463257,"responseEnd":396.7000000476837,"responseStart":396.7000000476837,"secureConnectionStart":179.09999990463257},{"duration":221.29999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":179.20000004768372,"connectEnd":179.20000004768372,"connectStart":179.20000004768372,"domainLookupEnd":179.20000004768372,"domainLookupStart":179.20000004768372,"fetchStart":179.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":179.20000004768372,"responseEnd":400.5,"responseStart":400.5,"secureConnectionStart":179.20000004768372},{"duration":221.89999985694885,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":179.20000004768372,"connectEnd":179.20000004768372,"connectStart":179.20000004768372,"domainLookupEnd":179.20000004768372,"domainLookupStart":179.20000004768372,"fetchStart":179.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":179.20000004768372,"responseEnd":401.09999990463257,"responseStart":401.09999990463257,"secureConnectionStart":179.20000004768372},{"duration":222.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":179.29999995231628,"connectEnd":179.29999995231628,"connectStart":179.29999995231628,"domainLookupEnd":179.29999995231628,"domainLookupStart":179.29999995231628,"fetchStart":179.29999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":179.29999995231628,"responseEnd":401.39999985694885,"responseStart":401.39999985694885,"secureConnectionStart":179.29999995231628},{"duration":222.40000009536743,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":179.39999985694885,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":179.39999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":401.7999999523163,"responseStart":0,"secureConnectionStart":0},{"duration":222.39999985694885,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":179.5,"connectEnd":179.5,"connectStart":179.5,"domainLookupEnd":179.5,"domainLookupStart":179.5,"fetchStart":179.5,"redirectEnd":0,"redirectStart":0,"requestStart":179.5,"responseEnd":401.89999985694885,"responseStart":401.89999985694885,"secureConnectionStart":179.5},{"duration":222.79999995231628,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":179.59999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":179.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":402.39999985694885,"responseStart":0,"secureConnectionStart":0},{"duration":223,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":179.70000004768372,"connectEnd":179.70000004768372,"connectStart":179.70000004768372,"domainLookupEnd":179.70000004768372,"domainLookupStart":179.70000004768372,"fetchStart":179.70000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":179.70000004768372,"responseEnd":402.7000000476837,"responseStart":402.7000000476837,"secureConnectionStart":179.70000004768372},{"duration":396.39999985694885,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":180.5,"connectEnd":180.5,"connectStart":180.5,"domainLookupEnd":180.5,"domainLookupStart":180.5,"fetchStart":180.5,"redirectEnd":0,"redirectStart":0,"requestStart":180.5,"responseEnd":576.8999998569489,"responseStart":576.8999998569489,"secureConnectionStart":180.5},{"duration":919.7000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":180.5,"connectEnd":180.5,"connectStart":180.5,"domainLookupEnd":180.5,"domainLookupStart":180.5,"fetchStart":180.5,"redirectEnd":0,"redirectStart":0,"requestStart":180.5,"responseEnd":1100.2000000476837,"responseStart":1100.2000000476837,"secureConnectionStart":180.5},{"duration":483.19999980926514,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":580.2000000476837,"connectEnd":580.2000000476837,"connectStart":580.2000000476837,"domainLookupEnd":580.2000000476837,"domainLookupStart":580.2000000476837,"fetchStart":580.2000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":580.2000000476837,"responseEnd":1063.3999998569489,"responseStart":1063.3999998569489,"secureConnectionStart":580.2000000476837},{"duration":362,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":753,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":753,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1115,"responseStart":0,"secureConnectionStart":0}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":32,"responseStart":152,"responseEnd":155,"domLoading":176,"domInteractive":1118,"domContentLoadedEventStart":1119,"domContentLoadedEventEnd":1151,"domComplete":2052,"loadEventStart":2052,"loadEventEnd":2054,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1102},{"name":"bigPipe.sidebar-id.end","time":1102.7999999523163},{"name":"bigPipe.activity-panel-pipe-id.start","time":1102.8999998569489},{"name":"bigPipe.activity-panel-pipe-id.end","time":1105.0999999046326},{"name":"activityTabFullyLoaded","time":1158.5999999046326}],"measures":[],"correlationId":"fda882ecd64f4d","effectiveType":"4g","downlink":9.3,"rtt":0,"serverDuration":67,"dbReadsTimeInMs":10,"dbConnsTimeInMs":17,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}