Loading...
 
Skip to main content

History: MySQL SSL

Source of version: 12 (current)

Copy to clipboard
            ! MySQL SSL
Added in ((tiki12))

For some system, e.g. cloud based systems such as ((Windows Azure)) or ((AWS Lightsail)), it is recommended to use an SSL connection to the MySQL database.

To enable a MySQL SSL connection, key files must be specified, in PEM format.
Depending on the case, only the CA can be sufficient to configure an SSL Connection (like for AWS Lightsail and Azure Database for MySQL flexible server) or the following 3 files are required.
* Client key. Filename must end with __-key.pem__
* Client cert. Filename must end with __-cert.pem__
* CA cert. Filename must end with __-ca.pem__
These files are placed in the ''tikiroot''/__db/cert__ folder. Tiki will detect these files and initiate an SSL connection. The db/cert folder could look something like this (Azure Clear DB sample).
See [https://dev.mysql.com/doc/refman/8.0/en/creating-ssl-files-using-openssl.html|how] you can create SSL certificates and keys using openssl for MySQL.

{img fileId="847"}
''Note: It is assumed that the folder only contains 1 set of keys''.

The MySQL SSL status can be checked in the Admin / Security panel. 
{img fileId="848"}
Starting in Tiki 12.1, the check can also be run from tiki-check.php

If any one of the key files are missing, a regular non-SSL connection is used.

Connecting using SSL requires 
* PHP extension php_openssl.dll must be enabled
* The MySQL server has activated SSL
* Tiki is configured with the 3 key files.