Áú»¢¶Ä²©

5 §³§Ú§Ô§å§â§ß§Ñ §Ó§Ö§Ù§Ñ §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ

§±§â§Ö§Ô§Ý§Ö§Õ

§°§Ó§Ñ §ã§Ö§Ü§è§Ú?§Ñ §á§â§å§Ø§Ñ Áú»¢¶Ä²© §Ü§à§â§Ñ§Ü§Ö §Ù§Ñ §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ö §Ú §á§â§Ú§Þ§Ö§â§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú?§Ö §Ù§Ñ §ã§Ú§Ô§å§â§ß§Ö TLS §Ó§Ö§Ù§Ö §Ú§Ù§Þ§Ö?§å:

Database Áú»¢¶Ä²© components
MySQL Áú»¢¶Ä²© §Ü§à§â§Ú§ã§ß§Ú§é§Ü§Ú §Ú§ß§ä§Ö§â§æ§Ö?§ã, Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â, Áú»¢¶Ä²© §á§â§à§Ü§ã§Ú
PostgreSQL Áú»¢¶Ä²© §Ü§à§â§Ú§ã§ß§Ú§é§Ü§Ú §Ú§ß§ä§Ö§â§æ§Ö?§ã, Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â, Áú»¢¶Ä²© §á§â§à§Ü§ã§Ú

§¥§Ñ §Ò§Ú§ã§ä§Ö §á§à§Õ§Ö§ã§Ú§Ý§Ú §ê§Ú§æ§â§à§Ó§Ñ§ß§å §Ó§Ö§Ù§å §å§ß§å§ä§Ñ§â DBMS-§Ñ, §á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ó§Ñ§ß§Ú§é§ß§å §Õ§à§Ü§å§Þ§Ö§ß§ä§Ñ§è§Ú?§å §á§â§à§Ú§Ù§Ó§à?§Ñ§é§Ñ §Ù§Ñ §Õ§Ö§ä§Ñ?§Ö:

  • : §Ú§Ù§Ó§à§â§ß§Ú §Ú §â§Ö§á§Ý§Ú§Ü§Ñ§ä§Ú§Ó§ß§Ú §ã§Ö§â§Ó§Ö§â§Ú §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.
  • : §Ô§â§å§á§ß§Ñ §â§Ö§á§Ý§Ú§Ü§Ñ§è§Ú?§Ñ §Ú§ä§Õ. §ã§Ö§â§Ó§Ö§â§Ú §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.
  • §à§á§è§Ú?§Ö §ê§Ú§æ§â§à§Ó§Ñ?§Ñ.

§³§Ó§Ú §á§â§Ú§Þ§Ö§â§Ú §ã§å §Ù§Ñ§ã§ß§à§Ó§Ñ§ß§Ú §ß§Ñ GA §Ú§Ù§Õ§Ñ?§Ú§Þ§Ñ MySQL CE (8.0) and PgSQL (13) §Õ§à§ã§ä§å§á§ß§Ú§ç §á§â§Ö§Ü§à §Ù§Ó§Ñ§ß§Ú§é§ß§Ú§ç §â§Ö§á§à§Ù§Ú§ä§à§â§Ú?§Ñ §Ü§à?§Ú §Ü§à§â§Ú§ã§ä§Ö CentOS 8.

§©§Ñ§ç§ä§Ö§Ó§Ú

§©§Ñ §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ö §ê§Ú§æ§â§à§Ó§Ñ?§Ñ §á§à§ä§â§Ö§Ò§ß§à ?§Ö §ã§Ý§Ö§Õ§Ö?§Ö:

  • §°§á§Ö§â§Ñ§ä§Ú§Ó§ß§Ú §ã§Ú§ã§ä§Ö§Þ §á§à§Õ§â§Ø§Ñ§ß §à§Õ §ã§ä§â§Ñ§ß§Ö §á§â§à§Ô§â§Ñ§Þ§Ö§â§Ñ §ã§Ñ OpenSSL >=1.1.X §Ú§Ý§Ú §Ñ§Ý§ä§Ö§â§ß§Ñ§ä§Ú§Ó§Ñ.

§±§â§Ö§á§à§â§å§é§å?§Ö §ã§Ö §Ú§Ù§Ò§Ö§Ô§Ñ§Ó§Ñ?§Ö OS §å §ã§ä§Ñ§ä§å§ã§å §ß§Ñ §Ü§â§Ñ?§å §Ø§Ú§Ó§à§ä§ß§à§Ô §Ó§Ö§Ü§Ñ, §á§à§ã§Ö§Ò§ß§à §å §ã§Ý§å§é§Ñ?§å §ß§à§Ó§Ú§ç §Ú§ß§ã§ä§Ñ§Ý§Ñ§è§Ú?§Ñ

  • §®§à§ä§à§â §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ (RDBMS) §Ú§ß§ã§ä§Ñ§Ý§Ú§â§Ñ§ß §Ú §à§Õ§â§Ø§Ñ§Ó§Ñ§ß §à§Õ §ã§ä§â§Ñ§ß§Ö §Ù§Ó§Ñ§ß§Ú§é§ß§à§Ô §â§Ö§á§à§Ù§Ú§ä§à§â§Ú?§å§Þ§Ñ §Ü§à?§Ú §à§Ò§Ö§Ù§Ò§Ö?§å?§Ö §á§â§à§Ô§â§Ñ§Þ§Ö§â. §°§á§Ö§â§Ñ§ä§Ú§Ó§ß§Ú §ã§Ú§ã§ä§Ö§Þ§Ú §ã§Ö §é§Ö§ã§ä§à §Ú§ã§á§à§â§å§é§å?§å §ã§Ñ §Ù§Ñ§ã§ä§Ñ§â§Ö§Ý§Ú§Þ? §Ó§Ö§â§Ù§Ú?§Ñ§Þ§Ñ §ã§à§æ§ä§Ó§Ö§â§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ü§à?§Ö §ß§Ö §á§à§Õ§â§Ø§Ñ§Ó§Ñ?§å §Ö§ß§Ü§â§Ú§á§è§Ú?§å, §ß§Ñ §á§â§Ú§Þ§Ö§â, §ã§Ú§ã§ä§Ö§Þ§Ú §Ù§Ñ§ã§ß§à§Ó§Ñ§ß§Ú §ß§Ñ RHEL 7 §Ú PostgreSQL 9.2, §Ü§Ñ§à §Ú MariaDB 5.5 §Ò§Ö§Ù §á§à§Õ§â§ê§Ü§Ö §Ù§Ñ §Ö§ß§Ü§â§Ú§á§è§Ú?§å.
§´§Ö§â§Þ§Ú§ß§à§Ý§à§Ô§Ú?§Ñ

§±§à§ã§ä§Ñ§Ó?§Ñ?§Ö §à§Ó§Ö §à§á§è§Ú?§Ö §ß§Ñ§Þ§Ö?§Ö §Ü§à§â§Ú§ê?§Ö?§Ö TLS §Ü§à§ß§Ö§Ü§è§Ú?§Ö §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ú§Ù Áú»¢¶Ä²© server/proxy §Ú §Ü§à§â§Ú§ã§ß§Ú§é§Ü§Ú§Þ §Ú§ß§ä§Ö§â§æ§Ö?§ã§à§Þ §Ù§Ñ §Ò§Ñ§Ù§å §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ:

  • required - §å§ã§á§à§ã§ä§Ñ§Ó?§Ñ?§Ö §Ü§à§ß§Ö§Ü§è§Ú?§Ö §Ü§à§â§Ú§ê?§Ö?§Ö§Þ TLS-§Ñ §Ü§Ñ§à §ß§Ñ§é§Ú§ß §ä§â§Ñ§ß§ã§á§à§â§ä§Ñ §Ò§Ö§Ù §á§â§à§Ó§Ö§â§Ö §Ú§Õ§Ö§ß§ä§Ú§ä§Ö§ä§Ñ;
  • verify_ca - §å§ã§á§à§ã§ä§Ñ§Ó?§Ñ?§Ö §Ü§à§ß§Ö§Ü§è§Ú?§Ö §Ü§à§â§Ú§ê?§Ö?§Ö§Þ TLS-§Ñ §Ú §á§â§à§Ó§Ö§â§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ;
  • verify_full - §å§ã§á§à§ã§ä§Ñ§Ó?§Ñ?§Ö §Ü§à§ß§Ö§Ü§è§Ú?§Ö §Ü§à§â§Ú§ê?§Ö?§Ö§Þ TLS-§Ñ, §á§â§à§Ó§Ö§â§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ú §á§â§à§Ó§Ö§â§Ñ §Õ§Ñ §Ý§Ú ?§Ö §Ú§Õ§Ö§ß§ä§Ú§ä§Ö§ä §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ (CN) §ß§Ñ§Ó§Ö§Õ§Ö§ß §å DBHost-§å §à§Õ§Ô§à§Ó§Ñ§â§Ñ ?§Ö§ß§à§Þ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§å;

Áú»¢¶Ä²© §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú?§Ñ

§¬§à§â§Ú§ã§ß§Ú§é§Ü§Ú §Ú§ß§ä§Ö§â§æ§Ö?§ã §Ù§Ñ §Ò§Ñ§Ù§å §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ

§³§Ú§Ô§å§â§ß§Ñ §Ó§Ö§Ù§Ñ §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Þ§à§Ø§Ö §ã§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ú§ã§Ñ§ä§Ú §ä§à§Ü§à§Þ §Ú§ß§ã§ä§Ñ§Ý§Ñ§è§Ú?§Ö §Ü§à§â§Ú§ã§ß§Ú§é§Ü§à§Ô §Ú§ß§ä§Ö§â§æ§Ö?§ã§Ñ:

  • §°§Ù§ß§Ñ§é§Ú§ä§Ö §¦§ß§Ü§â§Ú§á§è§Ú?§å TLS §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §á§à?§Ö §Ù§Ñ §á§à§ä§Ó§â§Õ§å §å §¬§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú?§Ú DB §Ü§à§ß§Ö§Ü§è§Ú?§Ö §Ü§à§â§Ñ§Ü §Ù§Ñ §à§Þ§à§Ô§å?§Ñ§Ó§Ñ?§Ö §ä§â§Ñ§ß§ã§á§à§â§ä§ß§à§Ô §ê§Ú§æ§â§à§Ó§Ñ?§Ñ.
  • §°§Ù§ß§Ñ§é§Ú§ä§Ö §á§à?§Ö §Ù§Ñ §á§à§ä§Ó§â§Õ§å §£§Ö§â§Ú§æ§Ú§Ü§å? §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ü§à?§Ö §ã§Ö §á§à?§Ñ§Ó?§å?§Ö §Ü§Ñ§Õ§Ñ ?§Ö §á§à?§Ö TLS §Ö§ß§Ü§â§Ú§á§è§Ú?§Ñ §à§Ù§ß§Ñ§é§Ö§ß§à §Õ§Ñ §Ò§Ú §ã§Ö §à§Þ§à§Ô§å?§Ú§Ý§à §ê§Ú§æ§â§à§Ó§Ñ?§Ö §ã§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ú§Þ§Ñ.

§©§Ñ MySQL, §à§á§è§Ú§à§ß§à §á§à?§Ö TLS §ê§Ú§æ§â§à§Ó§Ñ?§Ö §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ ?§Ö §à§ß§Ö§Þ§à§Ô§å?§Ö§ß§à, §Ñ§Ü§à ?§Ö §¥§à§Þ§Ñ?§Ú§ß §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §á§à§ã§ä§Ñ§Ó?§Ö§ß §ß§Ñ localhost, ?§Ö§â §Ó§Ö§Ù§Ñ §Ü§à?§Ñ §Ü§à§â§Ú§ã§ä§Ú socket §Õ§Ñ§ä§à§ä§Ö§Ü§å (§ß§Ñ Unix-§å) §Ú§Ý§Ú §Õ§Ö?§Ö§ß§å §Þ§Ö§Þ§à§â§Ú?§å (§ß§Ñ Windows-§å) §ß§Ö §Þ§à§Ø§Ö §Ò§Ú§ä§Ú §ê§Ú§æ§â§à§Ó§Ñ§ß§Ñ.
§©§Ñ PostgreSQL, §à§á§è§Ú§à§ß§à §á§à?§Ö * TLS §Ö§ß§Ü§â§Ú§á§è§Ú?§Ñ* ?§Ö §à§ß§Ö§Þ§à§Ô§å?§Ö§ß§à, §Ñ§Ü§à §Ó§â§Ö§Õ§ß§à§ã§ä §á§à?§Ñ §¥§à§Þ§Ñ?§Ú§ß §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §á§à§é§Ú?§Ö §Ü§à§ã§à§Þ §è§â§ä§à§Þ §Ú§Ý§Ú ?§Ö §á§à?§Ö §á§â§Ñ§Ù§ß§à.

§³§Ý§Ö§Õ§Ö?§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú §á§à§ã§ä§Ñ?§å §Õ§à§ã§ä§å§á§ß§Ú §å TLS §ê§Ú§æ§â§à§Ó§Ñ?§å §å §â§Ö§Ø§Ú§Þ§å §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ (§Ñ§Ü§à §ã§å §à§Ù§ß§Ñ§é§Ö§ß§Ñ §à§Ò§Ñ §á§à?§Ñ §Ù§Ñ §á§à§ä§Ó§â§Õ§å):

Parameter Description
§¥§Ñ§ä§à§ä§Ö§Ü§Ñ TLS CA §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §Ü§à§Þ§á§Ý§Ö§ä§ß§å §á§å§ä§Ñ?§å §Õ§à §Ó§Ñ§Ø§Ö?§Ö§Ô TLS §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ (CA) §Õ§Ñ§ä§à§ä§Ö§Ü§Ö.
§¥§Ñ§ä§à§ä§Ö§Ü§Ñ TLS §Ü?§å§é§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §Ü§à§Þ§á§Ý§Ö§ä§ß§å §á§å§ä§Ñ?§å §Õ§à §Ó§Ñ§Ø§Ö?§Ö TLS §Õ§Ñ§ä§à§ä§Ö§Ü§Ö §Ü?§å§é§Ñ.
§¥§Ñ§ä§à§ä§Ö§Ü§Ñ TLS §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §Ü§à§Þ§á§Ý§Ö§ä§ß§å §á§å§ä§Ñ?§å §Õ§à §Ó§Ñ§Ø§Ö?§Ö §Õ§Ñ§ä§à§ä§Ö§Ü§Ö TLS §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ.
§£§Ö§â§Ú§æ§Ú§Ü§Ñ§è§Ú?§Ñ §Õ§à§Þ§Ñ?§Ú§ß§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §°§Ù§ß§Ñ§é§Ú§ä§Ö §à§Ó§à §á§à?§Ö §Ù§Ñ §á§à§ä§Ó§â§Õ§å §Õ§Ñ §Ò§Ú§ã§ä§Ö §Ñ§Ü§ä§Ú§Ó§Ú§â§Ñ§Ý§Ú §Ó§Ö§â§Ú§æ§Ú§Ü§Ñ§è§Ú?§å §Õ§à§Þ§Ñ?§Ú§ß§Ñ.
§°§ß§Ö§Þ§à§Ô§å?§Ö§ß§à §Ù§Ñ MYSQL, ?§Ö§â PHP MySQL §Ò§Ú§Ò§Ý§Ú§à§ä§Ö§Ü§Ñ §ß§Ö §Õ§à§Ù§Ó§à?§Ñ§Ó§Ñ §á§â§Ö§ã§Ü§Ñ§Ü§Ñ?§Ö §Ü§à§â§Ñ§Ü§Ñ §Ó§Ñ§Ý§Ú§Õ§Ñ§è§Ú?§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ã§Ö§â§Ó§Ö§â§Ñ.
§­§Ú§ã§ä§Ñ TLS §ê§Ú§æ§Ñ§â§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§å §Ý§Ú§ã§ä§å §Ó§Ñ§Ø§Ö?§Ú§ç §ê§Ú§æ§Ñ§â§Ñ. §¶§à§â§Þ§Ñ§ä §Ý§Ú§ã§ä§Ö §ê§Ú§æ§Ñ§â§Ñ §Þ§à§â§Ñ §Ò§Ú§ä§Ú §å §ã§Ü§Ý§Ñ§Õ§å §ã§Ñ OpenSSL §ã§ä§Ñ§ß§Õ§Ñ§â§Õ§à§Þ.
§¥§à§ã§ä§å§á§ß§à §ã§Ñ§Þ§à §Ù§Ñ MySQL.

TLS §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú §Þ§à§â§Ñ?§å §Õ§Ñ §å§Ü§Ñ§Ù§å?§å §ß§Ñ §Ó§Ñ§Ø§Ö?§Ö §Õ§Ñ§ä§à§ä§Ö§Ü§Ö. §¡§Ü§à §à§ß§Ú §å§Ü§Ñ§Ù§å?§å §ß§Ñ §ß§Ö§á§à§ã§ä§à?§Ö?§Ö §Ú§Ý§Ú §ß§Ö§Ó§Ñ§Ø§Ö?§Ö §Õ§Ñ§ä§à§ä§Ö§Ü§Ö, §ä§à ?§Ö §Õ§à§Ó§Ö§ã§ä§Ú §Õ§à §Ô§â§Ö§ê§Ü§Ö §á§â§Ú §Ñ§å§ä§à§â§Ú§Ù§Ñ§è§Ú?§Ú.
§¡§Ü§à §ã§Ö §å §Õ§Ñ§ä§à§ä§Ö§Ü§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Þ§à§Ø§Ö §á§Ú§ã§Ñ§ä§Ú, §Ü§à§â§Ú§ã§ß§Ú§é§Ü§Ú §Ú§ß§ä§Ö§â§æ§Ö?§ã §Ô§Ö§ß§Ö§â§Ú§ê§Ö §å§á§à§Ù§à§â§Ö?§Ö §å §³§Ú§ã§ä§Ö§Þ§ã§Ü§Ú§Þ §Ú§ß§æ§à§â§Þ§Ñ§è§Ú?§Ñ§Þ§Ñ §ã§Ñ §Ú§Ù§Ó§Ö§ê§ä§Ñ?§Ö§Þ §Õ§Ñ "§¥§Ñ§ä§à§ä§Ö§Ü§Ö §´§­§³ §Õ§Ñ§ä§à§ä§Ö§Ü§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Þ§à§â§Ñ?§å §Ò§Ú§ä§Ú §ã§Ñ§Þ§à §Ù§Ñ §é§Ú§ä§Ñ?§Ö." (§á§â§Ú§Ü§Ñ§Ù§å?§Ö §ã§Ö §ã§Ñ§Þ§à §Ñ§Ü§à ?§Ö PHP §Ü§à§â§Ú§ã§ß§Ú§Ü §Ó§Ý§Ñ§ã§ß§Ú§Ü §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ).

§³§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ú §Ù§Ñ§ê§ä§Ú?§Ö§ß§Ú §Ý§à§Ù§Ú§ß§Ü§Ñ§Þ§Ñ §ß§Ú§ã§å §á§à§Õ§â§Ø§Ñ§ß§Ú.

§±§â§Ú§Þ§Ö§â§Ú §å§á§à§ä§â§Ö§Ò§Ö

Áú»¢¶Ä²© §Ü§à§â§Ú§ã§ß§Ú§é§Ü§Ú §Ú§ß§ä§Ö§â§æ§Ö?§ã §Ü§à§â§Ú§ã§ä§Ú GUI §Ú§ß§ä§Ö§â§æ§Ö?§ã §Ù§Ñ §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ?§Ö §Þ§à§Ô§å?§Ú§ç §à§á§è§Ú?§Ñ: required, verify_ca, verify_full. §±§à§ä§â§Ö§Ò§ß§Ö §à§á§è§Ú?§Ö §ß§Ñ§Ó§à§Õ§Ö §ã§Ö §ä§à§Ü§à§Þ §Ú§ß§ã§ä§Ñ§Ý§Ñ§è§Ú?§Ö §å §Ü§à§â§Ñ§Ü§å §é§Ñ§â§à§Ò?§Ñ§Ü§Ñ §Ù§Ñ §Ú§ß§ã§ä§Ñ§Ý§Ñ§è§Ú?§å §¬§à§ß§æ§Ú§Ô§å§â§Ú§ã§Ñ?§Ö DB §Ü§à§ß§Ö§Ü§è§Ú?§Ñ. §°§Ó§Ö §à§á§è§Ú?§Ö §ã§Ö §Þ§Ñ§á§Ú§â§Ñ?§å §å §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§à§ß§å §Õ§Ñ§ä§à§ä§Ö§Ü§å (zabbix.conf.php) §ß§Ñ §ã§Ý§Ö§Õ§Ö?§Ú §ß§Ñ§é§Ú§ß:

GUI settings Configuration file Description Result
...
// §¬§à§â§Ú§ã§ä§Ú §ã§Ö §Ù§Ñ TLS §Ü§à§ß§Ö§Ü§è§Ú?§å.
$DB['ENCRYPTION'] = true;
$DB['KEY_FILE'] = '';
$DB['CERT_FILE'] = '';
$DB['CA_FILE'] = '';
$DB['VERIFY_HOST'] = false;
$DB['CIPHER_LIST'] = '';
...
§±§â§à§Ó§Ö§â§Ú§ä§Ö TLS §ê§Ú§æ§â§à§Ó§Ñ?§Ö §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
§°§ã§ä§Ñ§Ó§Ú§ä§Ö §£§Ö§â§Ú§æ§Ú§Ü§Ñ§è§Ú?§å §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §ß§Ö§à§Ù§ß§Ñ§é§Ö§ß§Ú§Þ
§°§Þ§à§Ô§å?§Ú§ä§Ö required §â§Ö§Ø§Ú§Þ.
...
$DB['ENCRYPTION'] = true;
$DB['KEY_FILE'] = '';
$DB['CERT_FILE'] = '';
$DB['CA_FILE'] = '/etc/ssl/mysql/ca.pem';
$DB['VERIFY_HOST'] = false;
$DB['CIPHER_LIST'] = '';
...
1. §±§â§à§Ó§Ö§â§Ú§ä§Ö TLS §ê§Ú§æ§â§à§Ó§Ñ?§Ö §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ú §£§Ö§â§Ú§æ§Ú§Ü§å?§ä§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
2. §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §á§å§ä§Ñ?§å §Õ§à TLS CA §Õ§Ñ§ä§à§ä§Ö§Ü§Ö §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
§°§Þ§à§Ô§å?§Ú§ä§Ö §â§Ö§Ø§Ú§Þverify_ca.
...
// §¬§à§â§Ú§ã§ä§Ú §ã§Ö §Ù§Ñ TLS §Ü§à§ß§Ö§Ü§è§Ú?§å §ã§Ñ §ã§ä§â§à§Ô§à §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §Ý§Ú§ã§ä§à§Þ §ê§Ú§æ§â§à§Ó§Ñ?§Ñ.
$DB['ENCRYPTION'] = true;
$DB['KEY_FILE'] = '<key_file_path>';
$DB['CERT_FILE'] = '<key_file_path>';
$DB['CA_FILE'] = '<key_file_path>';
$DB['VERIFY_HOST'] = true;
$DB['CIPHER_LIST'] = '<cipher_list>';
...

§ª§Ý§Ú:

...
// §¬§à§â§Ú§ã§ä§Ú §ã§Ö §Ù§Ñ TLS §Ó§Ö§Ù§å §Ò§Ö§Ù §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§Ö §Ý§Ú§ã§ä§Ö §ê§Ú§æ§â§Ú - §Ú§Ù§Ñ§Ò§â§Ñ§ß §à§Õ §ã§ä§â§Ñ§ß§Ö MySQL §ã§Ö§â§Ó§Ö§â§Ñ
$DB['ENCRYPTION'] = true;
$DB['KEY_FILE'] = '<key_file_path>';
$DB['CERT_FILE'] = '<key_file_path>';
$DB['CA_FILE'] = '<key_file_path>';
$DB['VERIFY_HOST'] = true;
$DB['CIPHER_LIST'] = '';
...
1. §±§â§à§Ó§Ö§â§Ú§ä§Ö TLS §ê§Ú§æ§â§à§Ó§Ñ?§Ö §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ú §£§Ö§â§Ú§æ§Ú§Ü§à§Ó§Ñ?§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
2. §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §á§å§ä§Ñ?§å §Õ§à §¥§Ñ§ä§à§ä§Ö§Ü§Ö TLS §Ü?§å§é§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
3. §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §á§å§ä§Ñ?§å §Õ§à §´TLS CA §Õ§Ñ§ä§à§ä§Ö§Ü§Ö §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
4. §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §á§å§ä§Ñ?§å §Õ§à §Õ§Ñ§ä§à§ä§Ö§Ü§Ö TLS §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
5. §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö TLS §ê§Ú§æ§â§à§Ó§Ñ§ß§å §Ý§Ú§ã§ä§å (§à§á§è§Ú§à§ß§à)
§°§Þ§à§Ô§å?§Ú §â§Ö§Ø§Ú§Þ verify_full §Ù§Ñ MySQL.
...
$DB['ENCRYPTION'] = true;
$DB['KEY_FILE'] = '<key_file_path>';
$DB['CERT_FILE'] = '<key_file_path>';
$DB['CA_FILE'] = '<key_file_path>';
$DB['VERIFY_HOST'] = true;
$DB['CIPHER_LIST'] = ' ';
...
1. §±§â§à§Ó§Ö§â§Ú§ä§Ö * TLS §ê§Ú§æ§â§à§Ó§Ñ?§Ö §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ* §Ú §£§Ö§â§Ú§æ§Ú§Ü§å?§ä§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
2. §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §á§å§ä§Ñ?§å §Õ§à §¥§Ñ§ä§à§ä§Ö§Ü§Ö TLS §Ü?§å§é§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
3. §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §á§å§ä§Ñ?§å §Õ§à TLS CA §Õ§Ñ§ä§à§ä§Ö§Ü§Ö §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
4. §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §á§å§ä§Ñ?§å §Õ§à §¥§Ñ§ä§à§ä§Ö§Ü§Ö TLS §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
5. §±§â§à§Ó§Ö§â§Ú§ä§Ö §£§Ö§â§Ú§æ§Ú§Ü§Ñ§è§Ú?§å §Õ§à§Þ§Ñ?§Ú§ß§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ
§°§Þ§à§Ô§å?§Ú§ä§Ö §â§Ö§Ø§Ú§Þ verify_full §Ù§Ñ PostgreSQL.

§±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §ä§Ñ§Ü§à?§Ö: §±§â§Ú§Þ§Ö§â§Ú §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú?§Ö §ê§Ú§æ§â§à§Ó§Ñ?§Ñ §Ù§Ñ MySQL, §º§Ú§æ§â§à§Ó§Ñ?§Ö §á§â§Ú§Þ§Ö§â§Ñ §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú?§Ö §Ù§Ñ PostgreSQL.

Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â/§á§â§à§Ü§ã§Ú §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú?§Ñ

§³§Ú§Ô§å§â§ß§Ö §Ü§à§ß§Ö§Ü§è§Ú?§Ö §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Þ§à§Ô§å §ã§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ú§ã§Ñ§ä§Ú §ã§Ñ §à§Õ§Ô§à§Ó§Ñ§â§Ñ?§å?§Ú§Þ §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú§Þ§Ñ §å Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§å §Ú/§Ú§Ý§Ú §á§â§à§Ü§ã§Ú §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§à§ß§à? §Õ§Ñ§ä§à§ä§Ö§è§Ú.

Configuration Result
None §£§Ö§Ù§Ñ §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ò§Ö§Ù §ê§Ú§æ§â§à§Ó§Ñ?§Ñ.
1. Set DBTLSConnect=required §³§Ö§â§Ó§Ö§â/§á§â§à§Ü§ã§Ú §å§ã§á§à§ã§ä§Ñ§Ó?§Ñ TLS §Ü§à§ß§Ö§Ü§è§Ú?§å §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ. §¯§Ö§ê§Ú§æ§â§à§Ó§Ñ§ß§Ñ §Ó§Ö§Ù§Ñ §ß§Ú?§Ö §Õ§à§Ù§Ó§à?§Ö§ß§Ñ.
1. §±§à§ã§ä§Ñ§Ó§Ú§ä§Ö DBTLSConnect=verify_ca
2. §±§à§Õ§Ö§ã§Ú§ä§Ú DBTLSCAFile - §à§Õ§â§Ö§Õ§Ú§ä§Ö §Õ§Ñ§ä§à§ä§Ö§Ü§å §ã§Ñ TLS §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ §à§Ó§Ý§Ñ§ê?§Ö?§Ñ
§³§Ö§â§Ó§Ö§â/§á§â§à§Ü§ã§Ú §å§ã§á§à§ã§ä§Ñ§Ó?§Ñ TLS §Ü§à§ß§Ö§Ü§è§Ú?§å §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §ß§Ñ§Ü§à§ß §Ó§Ö§â§Ú§æ§Ú§Ü§Ñ§è§Ú?§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.
1. §±§à§Õ§Ö§ã§Ú§ä§Ö DBTLSConnect=verify_full
2. §±§à§Õ§Ö§ã§Ú§ä§Ö DBTLSCAFile - §ß§Ñ§Ó§Ö§Õ§Ú§ä§Ö TLS §Õ§Ñ§ä§à§ä§Ö§Ü§å §Ñ§å§ä§à§â§Ú§ä§Ö§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ
§³§Ö§â§Ó§Ö§â/§á§â§à§Ü§ã§Ú §å§ã§á§à§ã§ä§Ñ§Ó?§Ñ TLS §Ó§Ö§Ù§å §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §ß§Ñ§Ü§à§ß §á§â§à§Ó§Ö§â§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ò§Ñ§Ù§Ö §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ú §Ú§Õ§Ö§ß§ä§Ú§ä§Ö§ä§Ñ §Õ§à§Þ§Ñ?§Ú§ß§Ñ §Ò§Ñ§Ù§Ö
1. §±§à§Õ§Ö§ã§Ú§ä§Ö DBTLSCAFile - §ß§Ñ§Ó§Ö§Õ§Ú§ä§Ö TLS §Õ§Ñ§ä§à§ä§Ö§Ü§å §Ñ§å§ä§à§â§Ú§ä§Ö§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ
2. §±§à§Õ§Ö§ã§Ú§ä§Ö DBTLSCertFile - §ß§Ñ§Ó§Ö§Õ§Ú§ä§Ö §Õ§Ñ§ä§à§ä§Ö§Ü§å §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ ?§Ñ§Ó§ß§à§Ô §Ü?§å§é§Ñ §Ü§Ý§Ú?§Ö§ß§ä§Ñ
3. §±§à§Õ§Ö§ã§Ú§ä§Ö DBTLSKeyFile - §ß§Ñ§Ó§Ö§Õ§Ú§ä§Ö §Õ§Ñ§ä§à§ä§Ö§Ü§å §á§â§Ú§Ó§Ñ§ä§ß§à§Ô §Ü?§å§é§Ñ §Ü§Ý§Ú?§Ö§ß§ä§Ñ
§³§Ö§â§Ó§Ö§â/§á§â§à§Ü§ã§Ú §à§Ò§Ö§Ù§Ò§Ö?§å?§Ö §Ü§Ý§Ú?§Ö§ß§ä§ã§Ü§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §Õ§à§Ü §ã§Ö §á§à§Ó§Ö§Ù§å?§Ö §ã§Ñ §Ò§Ñ§Ù§à§Þ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.
1. §±§à§Õ§Ö§ã§Ú§ä§Ö DBTLSCipher - §Ý§Ú§ã§ä§å §ê§Ú§æ§â§à§Ó§Ñ?§Ñ §Ü§à?§Ö §Ü§Ý§Ú?§Ö§ß§ä §Õ§à§Ù§Ó§à?§Ñ§Ó§Ñ §Ù§Ñ §Ü§à§ß§Ö§Ü§è§Ú?§Ö §Ü§à?§Ö §Ü§à§â§Ú§ã§ä§Ö TLS §á§â§à§ä§à§Ü§à§Ý§Ö §Õ§à 1.2 §Ó§Ö§â§Ù§Ú?§Ö

§Ú§Ý§Ú DBTLSCipher13 - §Ý§Ú§ã§ä§å §ê§Ú§æ§Ñ§â§Ñ §Ü§à?§Ö §Ü§Ý§Ú?§Ö§ß§ä §Õ§à§Ù§Ó§à?§Ñ§Ó§Ñ §Ù§Ñ §Ó§Ö§Ù§Ö §Ü§à§â§Ú§ã§ä§Ö?§Ú TLS 1.3 §á§â§à§ä§à§Ü§à§Ý
(MySQL) TLS §Ü§à§ß§Ö§Ü§è§Ú?§Ñ §ã§Ö §Ó§â§ê§Ú §á§à§Þ§à?§å §ê§Ú§æ§â§Ö §ã§Ñ §ß§Ñ§Ó§Ö§Õ§Ö§ß§Ö §Ý§Ú§ã§ä§Ö.
(PostgreSQL) §±§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ö §à§Ó§Ö §à§á§è§Ú?§Ö §ã§Þ§Ñ§ä§â§Ñ §ã§Ö §Ô§â§Ö§ê§Ü§à§Þ.