|
|
|
@ -33,18 +33,16 @@ await command('openssl x509 -req -in /etc/mysql/ssl/client-req.pem -days 365000
|
|
|
|
|
|
|
|
|
|
await command('openssl verify -CAfile /etc/mysql/ssl/ca-cert.pem /etc/mysql/ssl/server-cert.pem /etc/mysql/ssl/client-cert.pem')
|
|
|
|
|
|
|
|
|
|
await command('cat >> /etc/mysql/my.cnf << EOF
|
|
|
|
|
[mysqld]
|
|
|
|
|
bind-address = 0.0.0.0
|
|
|
|
|
|
|
|
|
|
ssl-ca=/etc/mysql/ssl/ca-cert.pem
|
|
|
|
|
ssl-cert=/etc/mysql/ssl/server-cert.pem
|
|
|
|
|
ssl-key=/etc/mysql/ssl/server-key.pem
|
|
|
|
|
|
|
|
|
|
[client]
|
|
|
|
|
ssl-ca=/etc/mysql/ssl/ca-cert.pem
|
|
|
|
|
ssl-cert=/etc/mysql/ssl/client-cert.pem
|
|
|
|
|
ssl-key=/etc/mysql/ssl/client-key.pem')
|
|
|
|
|
await command('cat >> /etc/mysql/my.cnf << EOF' +
|
|
|
|
|
'[mysqld]' +
|
|
|
|
|
'bind-address = 0.0.0.0' +
|
|
|
|
|
'ssl-ca=/etc/mysql/ssl/ca-cert.pem' +
|
|
|
|
|
'ssl-cert=/etc/mysql/ssl/server-cert.pem' +
|
|
|
|
|
'ssl-key=/etc/mysql/ssl/server-key.pem' +
|
|
|
|
|
'[client]' +
|
|
|
|
|
'ssl-ca=/etc/mysql/ssl/ca-cert.pem' +
|
|
|
|
|
'ssl-cert=/etc/mysql/ssl/client-cert.pem' +
|
|
|
|
|
'ssl-key=/etc/mysql/ssl/client-key.pem')
|
|
|
|
|
|
|
|
|
|
await command('chown -R mysql:mysql /etc/mysql/ssl')
|
|
|
|
|
await command('chmod 644 /etc/mysql/ssl/*cert*')
|
|
|
|
|