CentOS7中配置Mysql5.7

CentOS7-Mysql5.7配置(四)

2019-05-25  本文已影响0人  Morphing0527

2.10.4 Securing the Initial MySQL Account

The MySQL installation process involves initializing the data directory, including the grant tables in the mysqlsystem database that define MySQL accounts. For details, see Section 2.10.1, “Initializing the Data Directory”.

This section describes how to assign a password to the initial root account created during the MySQL installation procedure, if you have not already done so.

Note

Alternative means for performing the process described in this section:

A password may already be assigned to the initial account under these circumstances:

The mysql.user grant table defines the initial MySQL user account and its access privileges. Installation of MySQL creates only a 'root'@'localhost' superuser account that has all privileges and can do anything. If the root account has an empty password, your MySQL installation is unprotected: Anyone can connect to the MySQL server as root without a password and be granted all privileges.

The 'root'@'localhost' account also has a row in the mysql.proxies_priv table that enables granting the PROXY privilege for ''@'', that is, for all users and all hosts. This enables root to set up proxy users, as well as to delegate to other accounts the authority to set up proxy users. See Section 6.2.14, “Proxy Users”.

To assign a password for the initial MySQL root account, use the following procedure. Replace root-password in the examples with the password that you want to use.

Start the server if it is not running. For instructions, see Section 2.10.2, “Starting the Server”.

The initial root account may or may not have a password. Choose whichever of the following procedures applies:

After assigning the root account a password, you must supply that password whenever you connect to the server using the account. For example, to connect to the server using the mysql client, use this command:

shell> mysql -u root -p
Enter password: (enter root password here)

To shut down the server with mysqladmin, use this command:

shell> mysqladmin -u root -p shutdown
Enter password: (enter root password here)

Note

For additional information about setting passwords, see Section 6.2.10, “Assigning Account Passwords”. If you forget your root password after setting it, see Section B.4.3.2, “How to Reset the Root Password”.

To set up additional accounts, see Section 6.2.7, “Adding Accounts, Assigning Privileges, and Dropping Accounts”.

PREV HOME UP NEXT

User Comments

User comments in this section are, as the name implies, provided by MySQL users. The MySQL documentation team is not responsible for, nor do they endorse, any of the information provided here.

Posted by n/a n/a on August 23, 2017

For MySQL 5.7.16 on Ubuntu 16.04, the default authentication plugin for user 'root' (empty host) is 'auth_socket'. This basically means you cannot set a password for that user, and root is always allowed to log in if it uses the socket (i.e. 'localhost' as the host to connect to). This should be reasonable secure since only root can access that socket and if your root account is compromised, you're already dead in the water. If you want to set a password for the root account anyway, you can change the plugin to 'mysql_native_password':

update user set plugin='mysql_native_password' where user='root' and host='localhost';

and then change the root password.

上一篇下一篇

猜你喜欢

热点阅读