MySQL/MariaDB非双向SSL下如何移除ServerHello中的CertificateRequest?
Absolutely, you can eliminate the CertificateRequest message in the ServerHello when using one-way SSL with MySQL. Let's break down why this is happening and how to fix it step by step:
Why the CertificateRequest Shows Up
The CertificateRequest gets sent by MySQL for one of two key reasons:
- Your server configuration has enabled client certificate validation via the
require_x509parameter, forcing the server to ask for a client cert. - The specific MySQL user you created is configured to require a client certificate (using
REQUIRE X509in the user definition).
Step-by-Step Resolution
1. Check Current SSL Settings
First, confirm your server's SSL configuration by running this command in the MySQL shell:
SHOW VARIABLES LIKE '%ssl%';
Look for the require_x509 variable—if it’s set to ON, that’s the main trigger for the CertificateRequest.
2. Adjust the Server Configuration File
Open your MySQL config file (usually my.cnf on Linux, my.ini on Windows) and navigate to the [mysqld] section:
- Keep your existing server SSL certificate paths (these are required for one-way SSL):
ssl_ca = /path/to/ca.pem ssl_cert = /path/to/server-cert.pem ssl_key = /path/to/server-key.pem - Set
require_x509toOFF(or comment out the line if it exists):require_x509 = OFF - If you want to enforce all connections use SSL (but still skip client certs), keep this parameter enabled:
require_secure_transport = ON
3. Update the MySQL User's Requirements
Even if you fix the server config, if your user was created with REQUIRE X509, it will still demand a client certificate. Update the user to only require SSL (not a client cert) with this command:
ALTER USER 'your_username'@'%' REQUIRE SSL;
If you don’t need to enforce SSL for this user (though this is unlikely for one-way SSL setups), use:
ALTER USER 'your_username'@'%' REQUIRE NONE;
4. Restart MySQL Server
Apply the changes by restarting your MySQL service. For example:
- On Linux:
sudo systemctl restart mysql - On Windows: Use the Services manager to restart the MySQL service.
5. Verify the Fix
Connect to MySQL with an SSL-enabled client (e.g., mysql -u your_username -p --ssl-mode=REQUIRED) and check the SSL handshake. The ServerHello should no longer include a CertificateRequest message. You can also confirm the user’s settings with:
SHOW GRANTS FOR 'your_username'@'%';
内容的提问来源于stack exchange,提问作者Bee

