3.7 Ensure SSL Key Files Have Appropriate Permissions

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

When configured to use SSL/TLS, MySQL relies on key files, which are stored on the host's filesystem. These key files are subject to the host's permissions structure.

Solution

Execute the following commands at a terminal prompt to remediate this setting using the Value from the audit procedure:
chown mysql:mysql <ssl_key Value>
chmod 400 <ssl_key Value>

See Also

https://benchmarks.cisecurity.org/tools2/mysql/CIS_Oracle_MySQL_Enterprise_Edition_5.6_Benchmark_v1.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: ccf53b6559a9c745e5d2f6f5d90cd5e6fb04bb52c8b8d83bc6b66f3b96ce695d