Docker部署的Redash v7无法连接Amazon RDS MySQL 8.0.28报‘SSL connection error: unknown error number’的解决方案咨询
I've run into similar compatibility issues with older Python 2.7-based tools connecting to MySQL 8.0, so let's break down the problem and actionable solutions:
The root cause here is that Redash v7 runs on Python 2.7 paired with an outdated version of MySQLdb (likely MySQL-python <=1.2.5), which doesn't support the newer TLS protocols or certificate validation mechanisms used by MySQL 8.0.28. Redash v10 uses modern dependencies (Python 3.x + updated MySQL clients) which explains why it works without issues.
Here are three solutions, ordered by preference:
1. Upgrade the MySQL client in the Redash container
The most robust fix is to replace the old MySQL-python package with mysqlclient—a maintained fork that supports both Python 2.7 and MySQL 8.0:
- First, enter your running Redash container:
docker exec -it <your-redash-container-id/name> bash - Uninstall the outdated MySQL client:
pip uninstall -y MySQL-python - Install a compatible version of
mysqlclient(supports Python 2.7):pip install mysqlclient==1.4.6 - Restart Redash services to apply the change:
supervisorctl restart all
Test your Python script again—this should resolve the SSL error by adding proper MySQL 8.0 support.
2. Specify a compatible SSL cipher
If upgrading dependencies isn't feasible right now, you can force the connection to use an SSL cipher that the old MySQLdb understands:
- Modify your test script's SSL params to include a legacy cipher:
ssl_params = { 'ca': '/app/redash/query_runner/files/rds-combined-ca-bundle.pem', 'cipher': 'DHE-RSA-AES256-SHA' } - For Redash's built-in MySQL data source, add this to the Additional Parameters field:
ssl_cipher=DHE-RSA-AES256-SHA
This works by telling MySQL to use an encryption suite that the old client can handle.
3. Downgrade RDS TLS version (not recommended)
As a last resort (since this reduces connection security), you can adjust your RDS instance's parameter group to use a TLS version compatible with the old client:
- Go to the AWS RDS Console, find your instance's associated parameter group.
- Edit the
tls_versionparameter and set it toTLSv1.0. - Reboot your RDS instance to apply the change.
Again, this is a temporary fix—you should prioritize upgrading Redash or using the first solution to maintain secure connections.
After applying any of these fixes, run your test script to confirm the connection works:
python example.py
内容的提问来源于stack exchange,提问作者mythosil

