MySQL attempts to establish an encrypted connection by default using self-signed certificates.
Configuration options described in this section let you harden the configuration by using custom certificates and forcing certificate verification.
MySQL SSL configuration options are available only for the External MySQL Server, which is the recommended setup.
Windows configuration
In Windows, custom MySQL SSL can be configured using the Database settings in the License Statistics Manager. See Using the License Statistics Manager for more information.
Linux configuration
In Linux, custom MySQL SSL can be configured using the xflicstat.cfg file. Available settings in the xflicstat.cfg file include the following.
| Setting | Default | Description |
|---|---|---|
| MYSQL_SSL_VERIFY | FALSE | May be set to TRUE or FALSE. To force certificate verification, set it to TRUE. |
| MYSQL_SSL_KEYSTORE | INSTALLDIR/mysql_keystore.jks | Path to keystore with loaded certificate and its private key. By default, it tries to use mysql_keystore.jks file from the installation directory. |
| MYSQL_SSL_KEYSTORE_PASSWORD | empty | Password to keystore. |
