7.3 Unique Key/Cert

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Use of default certificates can allow an attacker to impersonate the MySQL server.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Do not use a default or example certificate. Generate a key specifically for MySQL.

See Also

https://workbench.cisecurity.org/files/1613