RHEL6下升级MySQL 5.7.21后遇ERROR 2026 SSL连接故障求助
Let's work through the likely causes of your SSL connection error—you're seeing SSL is required but the server doesn't support it even though you've configured SSL paths in my.cnf, and only connecting with --ssl-disabled works. Here's how to diagnose and fix this:
1. Confirm MySQL Server Has SSL Enabled
First, connect using the bypass flag to get into the server:
mysql -u myuser -p --ssl-disabled
Once logged in, run this query to check SSL status variables:
SHOW VARIABLES LIKE '%ssl%';
- Look for
have_ssl— it should returnYESif SSL is properly active. If it showsDISABLEDorNO, the server failed to load your certificates. - Double-check that
ssl_ca,ssl_cert, andssl_keymatch the paths you set inmy.cnf. If they don't, your config file might not be the one the server is actually using.
2. Fix Certificate File Permissions
MySQL runs under the mysql user by default, so it needs read access to your SSL files. Run these commands to check and adjust permissions:
# Check current ownership of certificate files ls -l /var/lib/mysql/*.pem # Set correct owner if needed chown mysql:mysql /var/lib/mysql/ca.pem /var/lib/mysql/server-cert.pem /var/lib/mysql/server-key.pem /var/lib/mysql/client-cert.pem /var/lib/mysql/client-key.pem # Lock down private keys (read-only for owner only) chmod 600 /var/lib/mysql/server-key.pem /var/lib/mysql/client-key.pem # Make CA and public certs readable by the server chmod 644 /var/lib/mysql/ca.pem /var/lib/mysql/server-cert.pem /var/lib/mysql/client-cert.pem
Restart the MySQL service after making these changes, then recheck SSL status.
3. Verify Your my.cnf Is Being Loaded
Since you're using RHEL6 with what looks like a Software Collections (SCL) MySQL setup, there might be multiple my.cnf files. Confirm which config the server uses:
mysqld --print-defaults | grep -A 5 -B 5 ssl
If the SSL paths don't match your configured values, you're probably editing the wrong file. For SCL installations, the active config is often at /opt/rh/mysql57/root/etc/my.cnf—check that location.
4. Check MySQL Error Log for SSL Startup Issues
Your error log is at /var/log/mysql55-mysqld.log—look for entries related to SSL during server startup:
grep -i "ssl\|cert" /var/log/mysql55-mysqld.log
You might see errors like Failed to setup SSL or Can't read certificate file, which will directly point to the problem (e.g., invalid path, corrupted file, or permission block).
5. Simplify Your SSL Cipher List
Your ssl-cipher configuration is extremely long, and some ciphers might not be supported by MySQL 5.7.21 or your system's OpenSSL version. Try simplifying it to a few modern, compatible options:
[mysqld] ssl-cipher=ECDHE-RSA-AES256-GCM-SHA384:AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:AES128-GCM-SHA256
Restart MySQL and test connecting without --ssl-disabled.
6. Validate Your Self-Signed Certificates
Ensure your certificates were generated correctly in PEM format (required for MySQL 5.7). Verify the server certificate against your CA:
openssl verify -CAfile /var/lib/mysql/ca.pem /var/lib/mysql/server-cert.pem
If this returns an error, regenerate your certificates using these steps:
# Generate CA key and certificate openssl genrsa 2048 > ca-key.pem openssl req -new -x509 -nodes -days 3650 -key ca-key.pem > ca.pem # Generate server key and signing request openssl req -newkey rsa:2048 -days 3650 -nodes -keyout server-key.pem > server-req.pem openssl rsa -in server-key.pem -out server-key.pem # Sign server certificate with CA openssl x509 -req -in server-req.pem -days 3650 -CA ca.pem -CAkey ca-key.pem -set_serial 01 > server-cert.pem # Generate client key and signing request openssl req -newkey rsa:2048 -days 3650 -nodes -keyout client-key.pem > client-req.pem openssl rsa -in client-key.pem -out client-key.pem # Sign client certificate with CA openssl x509 -req -in client-req.pem -days 3650 -CA ca.pem -CAkey ca-key.pem -set_serial 02 > client-cert.pem
Copy these new files to /var/lib/mysql and set the correct permissions as outlined earlier.
内容的提问来源于stack exchange,提问作者Satya

