We are using wildcard certificate and we are getting error, while connecting to localhost or even connecting to UNIX socket.
ERROR 2026 (HY000): TLS/SSL error: Validation of SSL server certificate failed
|
There is no problem when we disable ssl_key, ssl_cert and ssl_ca settings and server is generating selfsigned cert. (but this will break old clients certificate validation?)
Why localhost connection is validating certificate?
Why UNIX socket connection is validating certificate?
Why UNIX socket connection using SSL?
{"report":{"fcp":1835.7999999523163,"ttfb":985.6000000238419,"pageVisibility":"visible","entityId":130300,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"89ff0a25-0d29-413a-b802-cb54aa1aa901","navigationType":0,"readyForUser":1897,"redirectCount":0,"resourceLoadedEnd":1807.1999999284744,"resourceLoadedStart":990.1999999284744,"resourceTiming":[{"duration":272.3000000715256,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":990.1999999284744,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":990.1999999284744,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1262.5,"responseStart":0,"secureConnectionStart":0},{"duration":272.60000002384186,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":990.3999999761581,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":990.3999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1263,"responseStart":0,"secureConnectionStart":0},{"duration":403.2999999523163,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":990.6000000238419,"connectEnd":1265.7999999523163,"connectStart":1265.7999999523163,"domainLookupEnd":1265.7999999523163,"domainLookupStart":1265.7999999523163,"fetchStart":990.6000000238419,"redirectEnd":0,"redirectStart":0,"requestStart":1265.8999999761581,"responseEnd":1393.8999999761581,"responseStart":1285.6000000238419,"secureConnectionStart":1265.7999999523163},{"duration":435.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":990.6999999284744,"connectEnd":990.6999999284744,"connectStart":990.6999999284744,"domainLookupEnd":990.6999999284744,"domainLookupStart":990.6999999284744,"fetchStart":990.6999999284744,"redirectEnd":0,"redirectStart":0,"requestStart":1266.5,"responseEnd":1426.1999999284744,"responseStart":1279.6999999284744,"secureConnectionStart":990.6999999284744},{"duration":287.2000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":990.7999999523163,"connectEnd":990.7999999523163,"connectStart":990.7999999523163,"domainLookupEnd":990.7999999523163,"domainLookupStart":990.7999999523163,"fetchStart":990.7999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":1266.6000000238419,"responseEnd":1278,"responseStart":1277.3999999761581,"secureConnectionStart":990.7999999523163},{"duration":294.39999997615814,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":990.8999999761581,"connectEnd":990.8999999761581,"connectStart":990.8999999761581,"domainLookupEnd":990.8999999761581,"domainLookupStart":990.8999999761581,"fetchStart":990.8999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":1268.1999999284744,"responseEnd":1285.2999999523163,"responseStart":1284.2999999523163,"secureConnectionStart":990.8999999761581},{"duration":322.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":991.1000000238419,"connectEnd":991.1000000238419,"connectStart":991.1000000238419,"domainLookupEnd":991.1000000238419,"domainLookupStart":991.1000000238419,"fetchStart":991.1000000238419,"redirectEnd":0,"redirectStart":0,"requestStart":1268.6000000238419,"responseEnd":1313.6000000238419,"responseStart":1310.8999999761581,"secureConnectionStart":991.1000000238419},{"duration":276.90000009536743,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":991.1999999284744,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":991.1999999284744,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1268.1000000238419,"responseStart":0,"secureConnectionStart":0},{"duration":298.5,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":991.2999999523163,"connectEnd":991.2999999523163,"connectStart":991.2999999523163,"domainLookupEnd":991.2999999523163,"domainLookupStart":991.2999999523163,"fetchStart":991.2999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":1271.5,"responseEnd":1289.7999999523163,"responseStart":1288.8999999761581,"secureConnectionStart":991.2999999523163},{"duration":275.60000002384186,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":996.3999999761581,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":996.3999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1272,"responseStart":0,"secureConnectionStart":0},{"duration":302.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":996.5,"connectEnd":996.5,"connectStart":996.5,"domainLookupEnd":996.5,"domainLookupStart":996.5,"fetchStart":996.5,"redirectEnd":0,"redirectStart":0,"requestStart":1275.8999999761581,"responseEnd":1299,"responseStart":1297.6999999284744,"secureConnectionStart":996.5},{"duration":622.6000000238419,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":997.1999999284744,"connectEnd":997.1999999284744,"connectStart":997.1999999284744,"domainLookupEnd":997.1999999284744,"domainLookupStart":997.1999999284744,"fetchStart":997.1999999284744,"redirectEnd":0,"redirectStart":0,"requestStart":1608.8999999761581,"responseEnd":1619.7999999523163,"responseStart":1618.6000000238419,"secureConnectionStart":997.1999999284744},{"duration":809.7999999523163,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":997.3999999761581,"connectEnd":997.3999999761581,"connectStart":997.3999999761581,"domainLookupEnd":997.3999999761581,"domainLookupStart":997.3999999761581,"fetchStart":997.3999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":1795.6000000238419,"responseEnd":1807.1999999284744,"responseStart":1806.5,"secureConnectionStart":997.3999999761581},{"duration":195.29999995231628,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1586.3999999761581,"connectEnd":1586.3999999761581,"connectStart":1586.3999999761581,"domainLookupEnd":1586.3999999761581,"domainLookupStart":1586.3999999761581,"fetchStart":1586.3999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":1743.7999999523163,"responseEnd":1781.6999999284744,"responseStart":1780.5,"secureConnectionStart":1586.3999999761581}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":521,"responseStart":985,"responseEnd":993,"domLoading":988,"domInteractive":1957,"domContentLoadedEventStart":1957,"domContentLoadedEventEnd":1998,"domComplete":2644,"loadEventStart":2644,"loadEventEnd":2644,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1930.3999999761581},{"name":"bigPipe.sidebar-id.end","time":1931.1999999284744},{"name":"bigPipe.activity-panel-pipe-id.start","time":1931.2999999523163},{"name":"bigPipe.activity-panel-pipe-id.end","time":1933.1000000238419},{"name":"activityTabFullyLoaded","time":2017.1000000238419}],"measures":[],"correlationId":"e126bdbc21b762","effectiveType":"4g","downlink":9.2,"rtt":0,"serverDuration":105,"dbReadsTimeInMs":14,"dbConnsTimeInMs":23,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
The only reason I can think of is to not break existing applications that use
And because TLS is established before the user name is known, the server cannot force TLS only for those users that REQUIRE it.