You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MySQL/MariaDB非双向SSL下如何移除ServerHello中的CertificateRequest?

How to Remove CertificateRequest from MySQL ServerHello for One-Way SSL

Absolutely, you can eliminate the CertificateRequest message in the ServerHello when using one-way SSL with MySQL. Let's break down why this is happening and how to fix it step by step:

Why the CertificateRequest Shows Up

The CertificateRequest gets sent by MySQL for one of two key reasons:

  • Your server configuration has enabled client certificate validation via the require_x509 parameter, forcing the server to ask for a client cert.
  • The specific MySQL user you created is configured to require a client certificate (using REQUIRE X509 in the user definition).

Step-by-Step Resolution

1. Check Current SSL Settings

First, confirm your server's SSL configuration by running this command in the MySQL shell:

SHOW VARIABLES LIKE '%ssl%';

Look for the require_x509 variable—if it’s set to ON, that’s the main trigger for the CertificateRequest.

2. Adjust the Server Configuration File

Open your MySQL config file (usually my.cnf on Linux, my.ini on Windows) and navigate to the [mysqld] section:

  • Keep your existing server SSL certificate paths (these are required for one-way SSL):
    ssl_ca = /path/to/ca.pem
    ssl_cert = /path/to/server-cert.pem
    ssl_key = /path/to/server-key.pem
    
  • Set require_x509 to OFF (or comment out the line if it exists):
    require_x509 = OFF
    
  • If you want to enforce all connections use SSL (but still skip client certs), keep this parameter enabled:
    require_secure_transport = ON
    

3. Update the MySQL User's Requirements

Even if you fix the server config, if your user was created with REQUIRE X509, it will still demand a client certificate. Update the user to only require SSL (not a client cert) with this command:

ALTER USER 'your_username'@'%' REQUIRE SSL;

If you don’t need to enforce SSL for this user (though this is unlikely for one-way SSL setups), use:

ALTER USER 'your_username'@'%' REQUIRE NONE;

4. Restart MySQL Server

Apply the changes by restarting your MySQL service. For example:

  • On Linux:
    sudo systemctl restart mysql
    
  • On Windows: Use the Services manager to restart the MySQL service.

5. Verify the Fix

Connect to MySQL with an SSL-enabled client (e.g., mysql -u your_username -p --ssl-mode=REQUIRED) and check the SSL handshake. The ServerHello should no longer include a CertificateRequest message. You can also confirm the user’s settings with:

SHOW GRANTS FOR 'your_username'@'%';

内容的提问来源于stack exchange,提问作者Bee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:08:40