mirror of
https://github.com/MariaDB/server.git
synced 2025-01-17 04:22:27 +01:00
f8866f8f66
Initial support tested against OpenSSL 1.0.1, 1.0.2, 1.1.0, Yassl and LibreSSL not working on Windows with native SChannel support, due to wrong cipher mapping: Latter one requires push of CONC-241 fixes. Please note that OpenSSL 0.9.8 and OpenSSL 1.1.0 will not work: Even if the build succeeds, test cases will fail with various errors, especially when using different tls libraries or versions for client and server.
27 lines
1.4 KiB
Text
27 lines
1.4 KiB
Text
create user ssl_sslv3@localhost;
|
|
grant select on test.* to ssl_sslv3@localhost require cipher "AES128-SHA";
|
|
create user ssl_tls12@localhost;
|
|
grant select on test.* to ssl_tls12@localhost require cipher "AES128-SHA256";
|
|
TLS1.2 ciphers: user is ok with any cipher
|
|
Variable_name Value
|
|
Ssl_cipher AES128-SHA256
|
|
Variable_name Value
|
|
Ssl_cipher DHE-RSA-AES256-GCM-SHA384
|
|
TLS1.2 ciphers: user requires SSLv3 cipher AES128-SHA
|
|
ERROR 1045 (28000): Access denied for user 'ssl_sslv3'@'localhost' (using password: NO)
|
|
ERROR 1045 (28000): Access denied for user 'ssl_sslv3'@'localhost' (using password: NO)
|
|
TLS1.2 ciphers: user requires TLSv1.2 cipher AES128-SHA256
|
|
Variable_name Value
|
|
Ssl_cipher AES128-SHA256
|
|
ERROR 1045 (28000): Access denied for user 'ssl_tls12'@'localhost' (using password: NO)
|
|
SSLv3 ciphers: user is ok with any cipher
|
|
ERROR 2026 (HY000): SSL connection error: sslv3 alert handshake failure
|
|
ERROR 2026 (HY000): SSL connection error: sslv3 alert handshake failure
|
|
SSLv3 ciphers: user requires SSLv3 cipher AES128-SHA
|
|
ERROR 2026 (HY000): SSL connection error: sslv3 alert handshake failure
|
|
ERROR 2026 (HY000): SSL connection error: sslv3 alert handshake failure
|
|
SSLv3 ciphers: user requires TLSv1.2 cipher AES128-SHA256
|
|
ERROR 2026 (HY000): SSL connection error: sslv3 alert handshake failure
|
|
ERROR 2026 (HY000): SSL connection error: sslv3 alert handshake failure
|
|
drop user ssl_sslv3@localhost;
|
|
drop user ssl_tls12@localhost;
|