Commit d1a948cf authored by Julius Goryavsky's avatar Julius Goryavsky

MDEV-26211: Cluster joiner node is failed to start when using TLS

This commit adds support for reading new SSL configuration
options (ssl-ca, ssl-cert and ssl-key) if the [sst] section
with old options (tca, tcert and tkey) is missing in the config
file, even if not specified authentication mode via the ssl-mode
option. Before this change, new parameters were read only if the
ssl-mode option was present in the configuration file and it was
not equal to the 'DISABLED' value.

Also added diagnostics (information level) which warns the user
that due to the presence of the tca, tcert and/or tkey parameters
in the [sst] section, new SSL configuration options will be ignored
(if their values do not match the old ones).
parent 3b29315f
...@@ -166,7 +166,8 @@ get_keys() ...@@ -166,7 +166,8 @@ get_keys()
fi fi
if [ -z "$ekey" -a ! -r "$ekeyfile" ]; then if [ -z "$ekey" -a ! -r "$ekeyfile" ]; then
wsrep_log_error "FATAL: Either key or keyfile must be readable" wsrep_log_error "FATAL: Either key must be specified " \
"or keyfile must be readable"
exit 3 exit 3
fi fi
...@@ -448,9 +449,30 @@ encgroups='--mysqld|sst|xtrabackup' ...@@ -448,9 +449,30 @@ encgroups='--mysqld|sst|xtrabackup'
check_server_ssl_config() check_server_ssl_config()
{ {
tcert=$(parse_cnf "$encgroups" 'ssl-ca') # backward-compatible behavior:
tpem=$(parse_cnf "$encgroups" 'ssl-cert') tcert=$(parse_cnf 'sst' 'tca')
tkey=$(parse_cnf "$encgroups" 'ssl-key') tpem=$(parse_cnf 'sst' 'tcert')
tkey=$(parse_cnf 'sst' 'tkey')
# reading new ssl configuration options:
local tcert2=$(parse_cnf "$encgroups" 'ssl-ca')
local tpem2=$(parse_cnf "$encgroups" 'ssl-cert')
local tkey2=$(parse_cnf "$encgroups" 'ssl-key')
# if there are no old options, then we take new ones:
if [ -z "$tcert" -a -z "$tpem" -a -z "$tkey" ]; then
tcert="$tcert2"
tpem="$tpem2"
tkey="$tkey2"
# checking for presence of the new-style SSL configuration:
elif [ -n "$tcert2" -o -n "$tpem2" -o -n "$tkey2" ]; then
if [ "$tcert" != "$tcert2" -o \
"$tpem" != "$tpem2" -o \
"$tkey" != "$tkey2" ]
then
wsrep_log_info "new ssl configuration options (ssl-ca, ssl-cert " \
"and ssl-key) are ignored by SST due to presence " \
"of the tca, tcert and/or tkey in the [sst] section"
fi
fi
} }
read_cnf() read_cnf()
...@@ -463,18 +485,10 @@ read_cnf() ...@@ -463,18 +485,10 @@ read_cnf()
if [ $encrypt -eq 0 -o $encrypt -ge 2 ] if [ $encrypt -eq 0 -o $encrypt -ge 2 ]
then then
if [ "$tmode" != 'DISABLED' -o $encrypt -ge 2 ] if [ "$tmode" != 'DISABLED' -o $encrypt -ge 2 ]; then
then
tcert=$(parse_cnf 'sst' 'tca')
tpem=$(parse_cnf 'sst' 'tcert')
tkey=$(parse_cnf 'sst' 'tkey')
fi
if [ "$tmode" != 'DISABLED' ]; then
# backward-incompatible behavior
if [ -z "$tpem" -a -z "$tkey" -a -z "$tcert" ]; then
# no old-style SSL config in [sst]
check_server_ssl_config check_server_ssl_config
fi fi
if [ "$tmode" != 'DISABLED' ]; then
if [ 0 -eq $encrypt -a -n "$tpem" -a -n "$tkey" ] if [ 0 -eq $encrypt -a -n "$tpem" -a -n "$tkey" ]
then then
encrypt=3 # enable cert/key SSL encyption encrypt=3 # enable cert/key SSL encyption
...@@ -489,8 +503,12 @@ read_cnf() ...@@ -489,8 +503,12 @@ read_cnf()
ealgo=$(parse_cnf "$encgroups" 'encrypt-algo') ealgo=$(parse_cnf "$encgroups" 'encrypt-algo')
eformat=$(parse_cnf "$encgroups" 'encrypt-format' 'openssl') eformat=$(parse_cnf "$encgroups" 'encrypt-format' 'openssl')
ekey=$(parse_cnf "$encgroups" 'encrypt-key') ekey=$(parse_cnf "$encgroups" 'encrypt-key')
# The keyfile should be read only when the key
# is not specified or empty:
if [ -z "$ekey" ]; then
ekeyfile=$(parse_cnf "$encgroups" 'encrypt-key-file') ekeyfile=$(parse_cnf "$encgroups" 'encrypt-key-file')
fi fi
fi
wsrep_log_info "SSL configuration: CA='$tcert', CERT='$tpem'," \ wsrep_log_info "SSL configuration: CA='$tcert', CERT='$tpem'," \
"KEY='$tkey', MODE='$tmode', encrypt='$encrypt'" "KEY='$tkey', MODE='$tmode', encrypt='$encrypt'"
......
...@@ -165,7 +165,8 @@ get_keys() ...@@ -165,7 +165,8 @@ get_keys()
fi fi
if [ -z "$ekey" -a ! -r "$ekeyfile" ]; then if [ -z "$ekey" -a ! -r "$ekeyfile" ]; then
wsrep_log_error "FATAL: Either key or keyfile must be readable" wsrep_log_error "FATAL: Either key must be specified " \
"or keyfile must be readable"
exit 3 exit 3
fi fi
...@@ -450,9 +451,30 @@ encgroups='--mysqld|sst|xtrabackup' ...@@ -450,9 +451,30 @@ encgroups='--mysqld|sst|xtrabackup'
check_server_ssl_config() check_server_ssl_config()
{ {
tcert=$(parse_cnf "$encgroups" 'ssl-ca') # backward-compatible behavior:
tpem=$(parse_cnf "$encgroups" 'ssl-cert') tcert=$(parse_cnf 'sst' 'tca')
tkey=$(parse_cnf "$encgroups" 'ssl-key') tpem=$(parse_cnf 'sst' 'tcert')
tkey=$(parse_cnf 'sst' 'tkey')
# reading new ssl configuration options:
local tcert2=$(parse_cnf "$encgroups" 'ssl-ca')
local tpem2=$(parse_cnf "$encgroups" 'ssl-cert')
local tkey2=$(parse_cnf "$encgroups" 'ssl-key')
# if there are no old options, then we take new ones:
if [ -z "$tcert" -a -z "$tpem" -a -z "$tkey" ]; then
tcert="$tcert2"
tpem="$tpem2"
tkey="$tkey2"
# checking for presence of the new-style SSL configuration:
elif [ -n "$tcert2" -o -n "$tpem2" -o -n "$tkey2" ]; then
if [ "$tcert" != "$tcert2" -o \
"$tpem" != "$tpem2" -o \
"$tkey" != "$tkey2" ]
then
wsrep_log_info "new ssl configuration options (ssl-ca, ssl-cert " \
"and ssl-key) are ignored by SST due to presence " \
"of the tca, tcert and/or tkey in the [sst] section"
fi
fi
} }
read_cnf() read_cnf()
...@@ -465,18 +487,10 @@ read_cnf() ...@@ -465,18 +487,10 @@ read_cnf()
if [ $encrypt -eq 0 -o $encrypt -ge 2 ] if [ $encrypt -eq 0 -o $encrypt -ge 2 ]
then then
if [ "$tmode" != 'DISABLED' -o $encrypt -ge 2 ] if [ "$tmode" != 'DISABLED' -o $encrypt -ge 2 ]; then
then
tcert=$(parse_cnf 'sst' 'tca')
tpem=$(parse_cnf 'sst' 'tcert')
tkey=$(parse_cnf 'sst' 'tkey')
fi
if [ "$tmode" != 'DISABLED' ]; then
# backward-incompatible behavior
if [ -z "$tpem" -a -z "$tkey" -a -z "$tcert" ]; then
# no old-style SSL config in [sst]
check_server_ssl_config check_server_ssl_config
fi fi
if [ "$tmode" != 'DISABLED' ]; then
if [ 0 -eq $encrypt -a -n "$tpem" -a -n "$tkey" ] if [ 0 -eq $encrypt -a -n "$tpem" -a -n "$tkey" ]
then then
encrypt=3 # enable cert/key SSL encyption encrypt=3 # enable cert/key SSL encyption
...@@ -491,8 +505,12 @@ read_cnf() ...@@ -491,8 +505,12 @@ read_cnf()
ealgo=$(parse_cnf "$encgroups" 'encrypt-algo') ealgo=$(parse_cnf "$encgroups" 'encrypt-algo')
eformat=$(parse_cnf "$encgroups" 'encrypt-format' 'xbcrypt') eformat=$(parse_cnf "$encgroups" 'encrypt-format' 'xbcrypt')
ekey=$(parse_cnf "$encgroups" 'encrypt-key') ekey=$(parse_cnf "$encgroups" 'encrypt-key')
# The keyfile should be read only when the key
# is not specified or empty:
if [ -z "$ekey" ]; then
ekeyfile=$(parse_cnf "$encgroups" 'encrypt-key-file') ekeyfile=$(parse_cnf "$encgroups" 'encrypt-key-file')
fi fi
fi
wsrep_log_info "SSL configuration: CA='$tcert', CERT='$tpem'," \ wsrep_log_info "SSL configuration: CA='$tcert', CERT='$tpem'," \
"KEY='$tkey', MODE='$tmode', encrypt='$encrypt'" "KEY='$tkey', MODE='$tmode', encrypt='$encrypt'"
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment