MDEV-33430Command line client error ERROR 2026 (HY000): TLS/SSL error: Server certificate validation failed. A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. Error 0x800B0109(CERT_E_UNTRUSTEDROOT)
To be more user-friendly in a typical passwordless test environment, mariadb cli, will disable --ssl-verify-server-cert if
--ssl-verify-server-cert was not enabled explicitly
CA was not specified
fingerprint was not specified
protocol is TCP
no password was provided
It'll also print a warning in this case
Sergei Golubchik
added a comment - To be more user-friendly in a typical passwordless test environment, mariadb cli, will disable --ssl-verify-server-cert if
--ssl-verify-server-cert was not enabled explicitly
CA was not specified
fingerprint was not specified
protocol is TCP
no password was provided
It'll also print a warning in this case
It makes MariaDB close to MySQL behavior (ssl_mode=PREFERRED by default).
So it reduce confusion of users who don't know difference between libmariadb and libmysql.
But use_ssl by default makes difficult to prohibit plaintext downgrade.
Inada Naoki
added a comment - `mysql_init()` now set `use_ssl=1` by default . Is this intended?
https://github.com/MariaDB/server/commit/abcd23add20276e4996773f578e77d5733e1b582#diff-b7189447363b2b74ee642549c398c1adcee11e2c8f4e0fa529dfde9d8f9e32faR1442
It makes MariaDB close to MySQL behavior (ssl_mode=PREFERRED by default).
So it reduce confusion of users who don't know difference between libmariadb and libmysql.
But use_ssl by default makes difficult to prohibit plaintext downgrade.
Was it intended that this change the default behavior of clients using mariadb-connector-c to require an SSL connection? Because that is the case now. This was very confusing for me to see the zabbix DB socket connection start to fail with `[2026] TLS/SSL error: SSL is required, but the server does not support it` when I hadn't actually configured SSL in the zabbix server configuration.
Orion Poplawski
added a comment - Was it intended that this change the default behavior of clients using mariadb-connector-c to require an SSL connection? Because that is the case now. This was very confusing for me to see the zabbix DB socket connection start to fail with ` [2026] TLS/SSL error: SSL is required, but the server does not support it` when I hadn't actually configured SSL in the zabbix server configuration.
https://github.com/mariadb-corporation/mariadb-connector-c/blame/3.4/plugins/auth/my_auth.c#L294
Yes, it was intended within the concept "secure by default" and it was added when the server started providing TLS automatically and without any configuration in MDEV-31856.
Supposedly, one can configure the client to disable TLS, if needed. Like, for the command line client it's --disable-ssl.
Sergei Golubchik
added a comment - Yes, it was intended within the concept "secure by default" and it was added when the server started providing TLS automatically and without any configuration in MDEV-31856 .
Supposedly, one can configure the client to disable TLS, if needed. Like, for the command line client it's --disable-ssl .
Anyway, we've added an opt-out recently for cases when a client doesn't have an option to disable TLS: https://github.com/mariadb-corporation/mariadb-connector-c/commit/39f2e12f9a6640eb82f1974dcd0ab2bc296c1403
People
Sergei Golubchik
Sergei Golubchik
Votes:
0Vote for this issue
Watchers:
10Start watching this issue
Dates
Created:
Updated:
Resolved:
Git Integration
Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.
{"report":{"fcp":1254.3999999761581,"ttfb":198.60000002384186,"pageVisibility":"visible","entityId":124005,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"f4029ed4-7df2-4130-82e5-2efea114cf5d","navigationType":0,"readyForUser":1327.8999999761581,"redirectCount":0,"resourceLoadedEnd":1212.3999999761581,"resourceLoadedStart":204.10000002384186,"resourceTiming":[{"duration":589.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":204.10000002384186,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":204.10000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":793.6000000238419,"responseStart":0,"secureConnectionStart":0},{"duration":589.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":204.39999997615814,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":204.39999997615814,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":793.8999999761581,"responseStart":0,"secureConnectionStart":0},{"duration":598.3999999761581,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":204.60000002384186,"connectEnd":204.60000002384186,"connectStart":204.60000002384186,"domainLookupEnd":204.60000002384186,"domainLookupStart":204.60000002384186,"fetchStart":204.60000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":204.60000002384186,"responseEnd":803,"responseStart":803,"secureConnectionStart":204.60000002384186},{"duration":659.1000000238419,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":204.69999998807907,"connectEnd":204.69999998807907,"connectStart":204.69999998807907,"domainLookupEnd":204.69999998807907,"domainLookupStart":204.69999998807907,"fetchStart":204.69999998807907,"redirectEnd":0,"redirectStart":0,"requestStart":204.69999998807907,"responseEnd":863.8000000119209,"responseStart":863.8000000119209,"secureConnectionStart":204.69999998807907},{"duration":662.3000000119209,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":205,"connectEnd":205,"connectStart":205,"domainLookupEnd":205,"domainLookupStart":205,"fetchStart":205,"redirectEnd":0,"redirectStart":0,"requestStart":205,"responseEnd":867.3000000119209,"responseStart":867.3000000119209,"secureConnectionStart":205},{"duration":662.6000000238419,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":205.19999998807907,"connectEnd":205.19999998807907,"connectStart":205.19999998807907,"domainLookupEnd":205.19999998807907,"domainLookupStart":205.19999998807907,"fetchStart":205.19999998807907,"redirectEnd":0,"redirectStart":0,"requestStart":205.19999998807907,"responseEnd":867.8000000119209,"responseStart":867.8000000119209,"secureConnectionStart":205.19999998807907},{"duration":662.8999999761581,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":205.30000001192093,"connectEnd":205.30000001192093,"connectStart":205.30000001192093,"domainLookupEnd":205.30000001192093,"domainLookupStart":205.30000001192093,"fetchStart":205.30000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":205.30000001192093,"responseEnd":868.1999999880791,"responseStart":868.1999999880791,"secureConnectionStart":205.30000001192093},{"duration":738.1999999880791,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":205.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":205.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":943.6999999880791,"responseStart":0,"secureConnectionStart":0},{"duration":663.0999999642372,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":205.60000002384186,"connectEnd":205.60000002384186,"connectStart":205.60000002384186,"domainLookupEnd":205.60000002384186,"domainLookupStart":205.60000002384186,"fetchStart":205.60000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":205.60000002384186,"responseEnd":868.6999999880791,"responseStart":868.6999999880791,"secureConnectionStart":205.60000002384186},{"duration":738.0999999642372,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":205.80000001192093,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":205.80000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":943.8999999761581,"responseStart":0,"secureConnectionStart":0},{"duration":663.2000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":205.89999997615814,"connectEnd":205.89999997615814,"connectStart":205.89999997615814,"domainLookupEnd":205.89999997615814,"domainLookupStart":205.89999997615814,"fetchStart":205.89999997615814,"redirectEnd":0,"redirectStart":0,"requestStart":205.89999997615814,"responseEnd":869.1000000238419,"responseStart":869.1000000238419,"secureConnectionStart":205.89999997615814},{"duration":773.7000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":207.39999997615814,"connectEnd":207.39999997615814,"connectStart":207.39999997615814,"domainLookupEnd":207.39999997615814,"domainLookupStart":207.39999997615814,"fetchStart":207.39999997615814,"redirectEnd":0,"redirectStart":0,"requestStart":207.39999997615814,"responseEnd":981.1000000238419,"responseStart":981.1000000238419,"secureConnectionStart":207.39999997615814},{"duration":957.4000000357628,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":207.39999997615814,"connectEnd":207.39999997615814,"connectStart":207.39999997615814,"domainLookupEnd":207.39999997615814,"domainLookupStart":207.39999997615814,"fetchStart":207.39999997615814,"redirectEnd":0,"redirectStart":0,"requestStart":207.39999997615814,"responseEnd":1164.800000011921,"responseStart":1164.800000011921,"secureConnectionStart":207.39999997615814},{"duration":53.59999996423721,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":954.8000000119209,"connectEnd":954.8000000119209,"connectStart":954.8000000119209,"domainLookupEnd":954.8000000119209,"domainLookupStart":954.8000000119209,"fetchStart":954.8000000119209,"redirectEnd":0,"redirectStart":0,"requestStart":954.8000000119209,"responseEnd":1008.3999999761581,"responseStart":1008.3999999761581,"secureConnectionStart":954.8000000119209},{"duration":198,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2bu7/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1014.1999999880791,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1014.1999999880791,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1212.199999988079,"responseStart":0,"secureConnectionStart":0},{"duration":197.79999995231628,"initiatorType":"link","name":"https://jira.mariadb.org/s/50bc9be5bfead1a25e72c1a9338c94f6-CDN/lu2bu7/820016/12ta74/e108c7645258ccb43280ed3404e3e949/_/download/contextbatch/css/com.atlassian.jira.plugins.jira-development-integration-plugin:0,-_super,-jira.view.issue,-jira.global,-jira.general,-jira.browse.project,-project.issue.navigator,-atl.general/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1014.6000000238419,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1014.6000000238419,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1212.3999999761581,"responseStart":0,"secureConnectionStart":0}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":24,"responseStart":199,"responseEnd":202,"domLoading":202,"domInteractive":1384,"domContentLoadedEventStart":1384,"domContentLoadedEventEnd":1433,"domComplete":1948,"loadEventStart":1948,"loadEventEnd":1949,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1361.1000000238419},{"name":"bigPipe.sidebar-id.end","time":1362},{"name":"bigPipe.activity-panel-pipe-id.start","time":1362.1000000238419},{"name":"bigPipe.activity-panel-pipe-id.end","time":1363.699999988079},{"name":"activityTabFullyLoaded","time":1453.8999999761581}],"measures":[],"correlationId":"6f229924ebb6a8","effectiveType":"4g","downlink":9.8,"rtt":0,"serverDuration":116,"dbReadsTimeInMs":19,"dbConnsTimeInMs":27,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
To be more user-friendly in a typical passwordless test environment, mariadb cli, will disable --ssl-verify-server-cert if
It'll also print a warning in this case