You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RHEL6下升级MySQL 5.7.21后遇ERROR 2026 SSL连接故障求助

Troubleshooting ERROR 2026 SSL Connection Issue with MySQL 5.7.21 on RHEL6

Let's work through the likely causes of your SSL connection error—you're seeing SSL is required but the server doesn't support it even though you've configured SSL paths in my.cnf, and only connecting with --ssl-disabled works. Here's how to diagnose and fix this:

1. Confirm MySQL Server Has SSL Enabled

First, connect using the bypass flag to get into the server:

mysql -u myuser -p --ssl-disabled

Once logged in, run this query to check SSL status variables:

SHOW VARIABLES LIKE '%ssl%';
  • Look for have_ssl — it should return YES if SSL is properly active. If it shows DISABLED or NO, the server failed to load your certificates.
  • Double-check that ssl_ca, ssl_cert, and ssl_key match the paths you set in my.cnf. If they don't, your config file might not be the one the server is actually using.

2. Fix Certificate File Permissions

MySQL runs under the mysql user by default, so it needs read access to your SSL files. Run these commands to check and adjust permissions:

# Check current ownership of certificate files
ls -l /var/lib/mysql/*.pem

# Set correct owner if needed
chown mysql:mysql /var/lib/mysql/ca.pem /var/lib/mysql/server-cert.pem /var/lib/mysql/server-key.pem /var/lib/mysql/client-cert.pem /var/lib/mysql/client-key.pem

# Lock down private keys (read-only for owner only)
chmod 600 /var/lib/mysql/server-key.pem /var/lib/mysql/client-key.pem
# Make CA and public certs readable by the server
chmod 644 /var/lib/mysql/ca.pem /var/lib/mysql/server-cert.pem /var/lib/mysql/client-cert.pem

Restart the MySQL service after making these changes, then recheck SSL status.

3. Verify Your my.cnf Is Being Loaded

Since you're using RHEL6 with what looks like a Software Collections (SCL) MySQL setup, there might be multiple my.cnf files. Confirm which config the server uses:

mysqld --print-defaults | grep -A 5 -B 5 ssl

If the SSL paths don't match your configured values, you're probably editing the wrong file. For SCL installations, the active config is often at /opt/rh/mysql57/root/etc/my.cnf—check that location.

4. Check MySQL Error Log for SSL Startup Issues

Your error log is at /var/log/mysql55-mysqld.log—look for entries related to SSL during server startup:

grep -i "ssl\|cert" /var/log/mysql55-mysqld.log

You might see errors like Failed to setup SSL or Can't read certificate file, which will directly point to the problem (e.g., invalid path, corrupted file, or permission block).

5. Simplify Your SSL Cipher List

Your ssl-cipher configuration is extremely long, and some ciphers might not be supported by MySQL 5.7.21 or your system's OpenSSL version. Try simplifying it to a few modern, compatible options:

[mysqld]
ssl-cipher=ECDHE-RSA-AES256-GCM-SHA384:AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:AES128-GCM-SHA256

Restart MySQL and test connecting without --ssl-disabled.

6. Validate Your Self-Signed Certificates

Ensure your certificates were generated correctly in PEM format (required for MySQL 5.7). Verify the server certificate against your CA:

openssl verify -CAfile /var/lib/mysql/ca.pem /var/lib/mysql/server-cert.pem

If this returns an error, regenerate your certificates using these steps:

# Generate CA key and certificate
openssl genrsa 2048 > ca-key.pem
openssl req -new -x509 -nodes -days 3650 -key ca-key.pem > ca.pem

# Generate server key and signing request
openssl req -newkey rsa:2048 -days 3650 -nodes -keyout server-key.pem > server-req.pem
openssl rsa -in server-key.pem -out server-key.pem

# Sign server certificate with CA
openssl x509 -req -in server-req.pem -days 3650 -CA ca.pem -CAkey ca-key.pem -set_serial 01 > server-cert.pem

# Generate client key and signing request
openssl req -newkey rsa:2048 -days 3650 -nodes -keyout client-key.pem > client-req.pem
openssl rsa -in client-key.pem -out client-key.pem

# Sign client certificate with CA
openssl x509 -req -in client-req.pem -days 3650 -CA ca.pem -CAkey ca-key.pem -set_serial 02 > client-cert.pem

Copy these new files to /var/lib/mysql and set the correct permissions as outlined earlier.


内容的提问来源于stack exchange,提问作者Satya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 03:59:33