Skip to content

Commit 19d3d3e

Browse files
committed
MDEV-16266 - New command FLUSH SSL to reload server's SSL certificate(private key,CRL,etc)
1 parent f570da5 commit 19d3d3e

File tree

13 files changed

+306
-202
lines changed

13 files changed

+306
-202
lines changed

include/mysql_com.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -231,6 +231,7 @@ enum enum_indicator_type
231231
#define REFRESH_DES_KEY_FILE (1ULL << 18)
232232
#define REFRESH_USER_RESOURCES (1ULL << 19)
233233
#define REFRESH_FOR_EXPORT (1ULL << 20) /* FLUSH TABLES ... FOR EXPORT */
234+
#define REFRESH_SSL (1ULL << 21)
234235

235236
#define REFRESH_GENERIC (1ULL << 30)
236237
#define REFRESH_FAST (1ULL << 31) /* Intern flag */

mysql-test/lib/generate-ssl-certs.sh

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,11 @@ openssl rsa -in server-key.pem -out server-key.pem
2121
# sign the server certificate with CA certificate
2222
openssl ca -keyfile cakey.pem -days 7300 -batch -cert cacert.pem -policy policy_anything -out server-cert.pem -infiles demoCA/server-req.pem
2323

24+
# Certificate with different validity period (MDEV-7598)
25+
openssl req -newkey rsa:1024 -keyout server-new-key.pem -out demoCA/server-new-req.pem -days 7301 -nodes -subj '/CN=server-new/C=FI/ST=Helsinki/L=Helsinki/O=MariaDB'
26+
openssl rsa -in server-new-key.pem -out server-new-key.pem
27+
openssl ca -keyfile cakey.pem -days 7301 -batch -cert cacert.pem -policy policy_anything -out server-new-cert.pem -infiles demoCA/server-new-req.pem
28+
2429
openssl req -newkey rsa:8192 -keyout server8k-key.pem -out demoCA/server8k-req.pem -days 7300 -nodes -subj '/CN=server8k/C=FI/ST=Helsinki/L=Helsinki/O=MariaDB'
2530
openssl rsa -in server8k-key.pem -out server8k-key.pem
2631
openssl ca -keyfile cakey.pem -days 7300 -batch -cert cacert.pem -policy policy_anything -out server8k-cert.pem -infiles demoCA/server8k-req.pem

mysql-test/main/flush_ssl.result

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
# Kill the server
2+
connect ssl_con,localhost,root,,,,,SSL;
3+
SELECT VARIABLE_VALUE INTO @ssl_not_after FROM INFORMATION_SCHEMA.SESSION_STATUS WHERE VARIABLE_NAME='Ssl_server_not_after';
4+
# Use a different certificate ("Not after" certificate field changed)
5+
FLUSH SSL;
6+
# Check new certificate used by new connection
7+
Result
8+
OK
9+
# Check that existing SSL connection still works, and uses old certificate, even if new one is loaded in FLUSH SSL
10+
connection ssl_con;
11+
SELECT IF(VARIABLE_VALUE=@ssl_not_after,'OK','FAIL') as Result FROM INFORMATION_SCHEMA.SESSION_STATUS WHERE VARIABLE_NAME='Ssl_server_not_after';
12+
Result
13+
OK
14+
disconnect ssl_con;
15+
connection default;
16+
SELECT VARIABLE_NAME NAME, VARIABLE_VALUE VALUE FROM INFORMATION_SCHEMA.GLOBAL_STATUS WHERE VARIABLE_NAME in ('Ssl_accepts', 'Ssl_finished_accepts');
17+
NAME VALUE
18+
SSL_ACCEPTS 1
19+
SSL_FINISHED_ACCEPTS 1
20+
FLUSH SSL;
21+
SELECT VARIABLE_NAME NAME, VARIABLE_VALUE VALUE FROM INFORMATION_SCHEMA.GLOBAL_STATUS WHERE VARIABLE_NAME in ('Ssl_accepts', 'Ssl_finished_accepts');
22+
NAME VALUE
23+
SSL_ACCEPTS 0
24+
SSL_FINISHED_ACCEPTS 0
25+
# Cleanup
26+
# Kill the server

mysql-test/main/flush_ssl.test

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
# MDEV-16266 Reload SSL certificate
2+
# This test reloads server SSL certs FLUSH SSL, and checks that
3+
# 1. old SSL connections (that existed before FLUSH) still work and use old certificate
4+
# 2. new SSL connection use new certificate
5+
# 3. if FLUSH SSL runs into error, SSL is still functioning
6+
# SWtatus variable Ssl_server_not_after is used to tell the old certificate from new.
7+
8+
9+
source include/have_ssl_communication.inc;
10+
11+
# Restart server with cert. files located in temp directory
12+
# We are going to remove / replace them within the test,
13+
# so we can't use the ones in std_data directly.
14+
15+
let $ssl_cert=$MYSQLTEST_VARDIR/tmp/ssl_cert.pem;
16+
let $ssl_key=$MYSQLTEST_VARDIR/tmp/ssl_key.pem;
17+
18+
copy_file $MYSQL_TEST_DIR/std_data/server-key.pem $ssl_key;
19+
copy_file $MYSQL_TEST_DIR/std_data/server-cert.pem $ssl_cert;
20+
21+
let $restart_parameters=--ssl-key=$ssl_key --ssl-cert=$ssl_cert;
22+
--source include/kill_mysqld.inc
23+
--source include/start_mysqld.inc
24+
25+
connect ssl_con,localhost,root,,,,,SSL;
26+
SELECT VARIABLE_VALUE INTO @ssl_not_after FROM INFORMATION_SCHEMA.SESSION_STATUS WHERE VARIABLE_NAME='Ssl_server_not_after';
27+
let $ssl_not_after=`SELECT @ssl_not_after`;
28+
29+
remove_file $ssl_cert;
30+
remove_file $ssl_key;
31+
32+
--echo # Use a different certificate ("Not after" certificate field changed)
33+
copy_file $MYSQL_TEST_DIR/std_data/server-new-key.pem $ssl_key;
34+
copy_file $MYSQL_TEST_DIR/std_data/server-new-cert.pem $ssl_cert;
35+
36+
FLUSH SSL;
37+
38+
--echo # Check new certificate used by new connection
39+
exec $MYSQL --ssl -e "SELECT IF(VARIABLE_VALUE <> '$ssl_not_after', 'OK', 'FAIL') as Result FROM INFORMATION_SCHEMA.SESSION_STATUS WHERE VARIABLE_NAME='Ssl_server_not_after'";
40+
41+
--echo # Check that existing SSL connection still works, and uses old certificate, even if new one is loaded in FLUSH SSL
42+
connection ssl_con;
43+
SELECT IF(VARIABLE_VALUE=@ssl_not_after,'OK','FAIL') as Result FROM INFORMATION_SCHEMA.SESSION_STATUS WHERE VARIABLE_NAME='Ssl_server_not_after';
44+
45+
disconnect ssl_con;
46+
connection default;
47+
48+
SELECT VARIABLE_NAME NAME, VARIABLE_VALUE VALUE FROM INFORMATION_SCHEMA.GLOBAL_STATUS WHERE VARIABLE_NAME in ('Ssl_accepts', 'Ssl_finished_accepts');
49+
FLUSH SSL;
50+
#Check that accepts are zeroed by FLUSH SSL.
51+
SELECT VARIABLE_NAME NAME, VARIABLE_VALUE VALUE FROM INFORMATION_SCHEMA.GLOBAL_STATUS WHERE VARIABLE_NAME in ('Ssl_accepts', 'Ssl_finished_accepts');
52+
53+
--echo # Cleanup
54+
remove_file $ssl_cert;
55+
remove_file $ssl_key;
56+
# restart with usuall SSL
57+
let $restart_parameters=;
58+
--source include/kill_mysqld.inc
59+
--source include/start_mysqld.inc
60+
61+
Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
Certificate:
2+
Data:
3+
Version: 3 (0x2)
4+
Serial Number: 7 (0x7)
5+
Signature Algorithm: sha256WithRSAEncryption
6+
Issuer: CN=cacert, C=FI, ST=Helsinki, L=Helsinki, O=MariaDB
7+
Validity
8+
Not Before: Dec 11 17:13:59 2018 GMT
9+
Not After : Dec 7 17:13:59 2038 GMT
10+
Subject: C=FI, ST=Helsinki, L=Helsinki, O=MariaDB, CN=server-new
11+
Subject Public Key Info:
12+
Public Key Algorithm: rsaEncryption
13+
Public-Key: (1024 bit)
14+
Modulus:
15+
00:c9:40:33:d7:fb:b7:a2:bc:4e:d4:65:27:1a:c9:
16+
da:8b:2e:fc:a9:60:1a:69:e8:fd:e3:13:78:b6:08:
17+
3b:3e:fd:d3:b0:d3:6c:a1:79:bd:85:ca:be:a1:0a:
18+
4e:2a:ee:2c:8d:da:72:e6:85:56:ec:3a:7c:46:a3:
19+
d3:18:e7:19:19:8d:14:7e:de:d2:a4:2f:22:56:1c:
20+
21:03:24:f6:2d:55:4e:49:25:9f:32:01:94:66:47:
21+
e4:fa:fa:45:b1:b7:33:26:da:f1:c7:29:3b:ba:fe:
22+
e8:d4:f1:fc:29:57:6b:3a:be:ef:2e:1d:da:ef:0a:
23+
d7:54:8d:67:00:7b:7a:29:2b
24+
Exponent: 65537 (0x10001)
25+
X509v3 extensions:
26+
X509v3 Basic Constraints:
27+
CA:FALSE
28+
Netscape Comment:
29+
OpenSSL Generated Certificate
30+
X509v3 Subject Key Identifier:
31+
FF:42:5E:88:AC:6A:C8:80:63:A8:AF:20:C6:BE:E8:A4:02:D5:42:AF
32+
X509v3 Authority Key Identifier:
33+
keyid:1C:C7:2B:AA:1B:B1:BB:2E:9A:F4:0F:B1:86:60:57:38:C2:41:05:12
34+
35+
Signature Algorithm: sha256WithRSAEncryption
36+
7c:cc:c1:93:43:83:a9:ea:19:9d:1c:a1:f8:e1:c1:61:58:c0:
37+
db:ef:43:6e:d7:cf:4d:75:38:6e:cb:03:25:5d:21:af:03:b1:
38+
86:5f:b3:d1:e2:6f:8c:89:55:b7:82:6a:c0:d6:46:08:0c:68:
39+
9d:ef:cc:2e:79:f5:d8:0b:f2:13:3a:52:cc:08:d5:3a:f0:d8:
40+
5c:9e:85:a7:38:31:9d:7c:61:2b:59:ee:c0:16:a6:16:dd:80:
41+
e2:ef:96:3d:b0:13:ec:9b:9a:91:69:3f:6c:46:87:05:55:b7:
42+
32:85:51:da:02:c3:ac:2d:c3:5e:9a:51:f8:96:75:0b:63:29:
43+
4e:47:47:f1:82:a6:ad:44:3d:51:b3:19:8b:ae:26:a9:15:a0:
44+
73:b6:70:6e:4f:72:9d:69:4e:b2:9b:2a:a8:50:87:b8:9f:c0:
45+
a7:37:0f:9e:bc:4c:80:b9:b8:47:28:8e:33:c3:7f:d7:fe:31:
46+
f0:a9:1c:7a:f7:a3:34:21:d4:e4:53:86:a3:7e:1d:1c:a7:65:
47+
fb:ec:f9:1f:17:1e:4f:19:f9:fe:dd:ee:53:0f:b5:98:b7:7a:
48+
ef:12:6c:8d:32:78:66:a5:42:d7:3d:a5:09:f8:06:05:a4:ff:
49+
bd:4e:e7:85:c4:f0:dc:dc:20:26:84:91:69:e8:cf:3b:27:9f:
50+
35:36:cc:ff
51+
-----BEGIN CERTIFICATE-----
52+
MIIDIjCCAgqgAwIBAgIBBzANBgkqhkiG9w0BAQsFADBWMQ8wDQYDVQQDDAZjYWNl
53+
cnQxCzAJBgNVBAYTAkZJMREwDwYDVQQIDAhIZWxzaW5raTERMA8GA1UEBwwISGVs
54+
c2lua2kxEDAOBgNVBAoMB01hcmlhREIwHhcNMTgxMjExMTcxMzU5WhcNMzgxMjA3
55+
MTcxMzU5WjBaMQswCQYDVQQGEwJGSTERMA8GA1UECAwISGVsc2lua2kxETAPBgNV
56+
BAcMCEhlbHNpbmtpMRAwDgYDVQQKDAdNYXJpYURCMRMwEQYDVQQDDApzZXJ2ZXIt
57+
bmV3MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJQDPX+7eivE7UZScaydqL
58+
LvypYBpp6P3jE3i2CDs+/dOw02yheb2Fyr6hCk4q7iyN2nLmhVbsOnxGo9MY5xkZ
59+
jRR+3tKkLyJWHCEDJPYtVU5JJZ8yAZRmR+T6+kWxtzMm2vHHKTu6/ujU8fwpV2s6
60+
vu8uHdrvCtdUjWcAe3opKwIDAQABo3sweTAJBgNVHRMEAjAAMCwGCWCGSAGG+EIB
61+
DQQfFh1PcGVuU1NMIEdlbmVyYXRlZCBDZXJ0aWZpY2F0ZTAdBgNVHQ4EFgQU/0Je
62+
iKxqyIBjqK8gxr7opALVQq8wHwYDVR0jBBgwFoAUHMcrqhuxuy6a9A+xhmBXOMJB
63+
BRIwDQYJKoZIhvcNAQELBQADggEBAHzMwZNDg6nqGZ0cofjhwWFYwNvvQ27Xz011
64+
OG7LAyVdIa8DsYZfs9Hib4yJVbeCasDWRggMaJ3vzC559dgL8hM6UswI1Trw2Fye
65+
hac4MZ18YStZ7sAWphbdgOLvlj2wE+ybmpFpP2xGhwVVtzKFUdoCw6wtw16aUfiW
66+
dQtjKU5HR/GCpq1EPVGzGYuuJqkVoHO2cG5Pcp1pTrKbKqhQh7ifwKc3D568TIC5
67+
uEcojjPDf9f+MfCpHHr3ozQh1ORThqN+HRynZfvs+R8XHk8Z+f7d7lMPtZi3eu8S
68+
bI0yeGalQtc9pQn4BgWk/71O54XE8NzcICaEkWnozzsnnzU2zP8=
69+
-----END CERTIFICATE-----
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
-----BEGIN RSA PRIVATE KEY-----
2+
MIICXQIBAAKBgQDJQDPX+7eivE7UZScaydqLLvypYBpp6P3jE3i2CDs+/dOw02yh
3+
eb2Fyr6hCk4q7iyN2nLmhVbsOnxGo9MY5xkZjRR+3tKkLyJWHCEDJPYtVU5JJZ8y
4+
AZRmR+T6+kWxtzMm2vHHKTu6/ujU8fwpV2s6vu8uHdrvCtdUjWcAe3opKwIDAQAB
5+
AoGBAKlH3dPxIdg6+TvjEe+Qlsm4bkKyWcV4fAaDnGfRqLQloej9DkUNOAPQNGUV
6+
XAb0bHmtpDSPODxgPaTVrH0n9o1tTXrfIijSM7zm0Ub2H7YPMNMUSae+9K3bdXoL
7+
aHjlYYXBXULa093nXOXNmjX17pBKUmiAkKCoqxTMx9QGW8rRAkEA/aqjdIrbaEJd
8+
Mky4bLzaSZITls/8+LPekUpH+TXdjgSMMaDxd4OXAnA34fssPOhsD8yzgeo2XZZj
9+
Snk4wfBHrwJBAMsaITNwvAXj3joX/eTD4Q/FcwdaPt4dL2BS13uJrva/TZGEAnOn
10+
n5nu2exZDslxyoKA5SBl2oZbhtCAA1elWUUCQQCeo8rZpcWVrHtQa76i8nCpthte
11+
I/EXMJYu0v+0EUXf/WQX3YllrvwP4FJyl3yREuIR93kD9I/Pc6/g8XLXhwetAkB1
12+
VG8BrIqyTGVA4kNGOPJ3jfVZtgTDg9CusKzTLULqQLGq8rwH3DoTTyyNoRUtwpLe
13+
uV+kS7LmE1HaeVl09IyRAkBXb/5p2D+Dfb/3/mx5/YuFNwB07sY+H0CrzO1qSo62
14+
q0nzNK3/irTzqtuerwy/YkBTz/T75GePIK4P0b9elNlb
15+
-----END RSA PRIVATE KEY-----

mysql-test/suite/perfschema/r/dml_setup_instruments.result

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,13 +22,13 @@ NAME ENABLED TIMED
2222
wait/synch/rwlock/sql/LOCK_dboptions YES YES
2323
wait/synch/rwlock/sql/LOCK_grant YES YES
2424
wait/synch/rwlock/sql/LOCK_SEQUENCE YES YES
25+
wait/synch/rwlock/sql/LOCK_ssl_refresh YES YES
2526
wait/synch/rwlock/sql/LOCK_system_variables_hash YES YES
2627
wait/synch/rwlock/sql/LOCK_sys_init_connect YES YES
2728
wait/synch/rwlock/sql/LOCK_sys_init_slave YES YES
2829
wait/synch/rwlock/sql/LOGGER::LOCK_logger YES YES
2930
wait/synch/rwlock/sql/MDL_context::LOCK_waiting_for YES YES
3031
wait/synch/rwlock/sql/MDL_lock::rwlock YES YES
31-
wait/synch/rwlock/sql/Query_cache_query::lock YES YES
3232
select * from performance_schema.setup_instruments
3333
where name like 'Wait/Synch/Cond/sql/%'
3434
and name not in (

0 commit comments

Comments
 (0)