MySQL 是最流行的开源关系型数据库管理系统之一。它运行快速、易于管理、可扩展,并且是流行的 LAMP 和 LEMP 堆栈的重要组成部分。MySQL 可以在任何平台上运行,包括 MacOS、Linux 和 Windows。
本文介绍如何在 Ubuntu 22.04 机器上安装并加固 MySQL 8.0 版本。完成后,您将拥有一个功能齐全的数据库服务器,可用于您的项目。
先决条件
要遵循本指南,您必须以具有 sudo 权限的用户身份登录。
在 Ubuntu 上安装 MySQL
撰写本文时,Ubuntu 22.04 存储库中可用的最新 MySQL 版本是 MySQL 8.0 版本。
首先更新本地软件包索引:
终端
sudo apt update接下来,您可以通过输入以下命令来安装 MySQL:
终端
sudo apt install mysql-server安装完成后,MySQL 服务将自动启动。要验证 MySQL 服务器是否正在运行,请输入:
终端
sudo systemctl status mysql输出应显示服务已启用并正在运行:
输出
● mysql.service - MySQL Community Server
Loaded: loaded (/lib/systemd/system/mysql.service; enabled; vendor preset: enabled)
Active: active (running) since Wed 2023-11-29 16:50:28 UTC; 49s ago
Process: 2238 ExecStartPre=/usr/share/mysql/mysql-systemd-start pre (code=exited, status=0/SUCCESS)
Main PID: 2246 (mysqld)
Status: "Server is operational"
Tasks: 38 (limit: 2220)
Memory: 365.3M
CPU: 1.199s
CGroup: /system.slice/mysql.service
└─2246 /usr/sbin/mysqld...如果由于某种原因服务器无法启动,您可以通过使用 journalctl 检查日志来排查问题:
终端
sudo journalctl -u mysql加固 MySQL
MySQL 安装附带一个名为 mysql_secure_installation 的脚本,允许您提高数据库服务器的安全性。
不带参数调用该脚本:
终端
sudo mysql_secure_installation您将收到提示以配置 VALIDATE PASSWORD PLUGIN,该插件用于测试 MySQL 用户密码的强度并提高安全性:
输出
Securing the MySQL server deployment.
Connecting to MySQL using a blank password.
VALIDATE PASSWORD COMPONENT can be used to test passwords
and improve security. It checks the strength of password
and allows the users to set only those passwords which are
secure enough. Would you like to setup VALIDATE PASSWORD component?
Press y|Y for Yes, any other key for No: y密码验证策略有三个级别:低、中和高。如果您要设置 validate password 插件,请按 y,或按其他键进入下一步。
如果您决定使用该组件,脚本将要求您选择密码复杂度和强度的级别。通常建议选择中等或高强度:
输出
There are three levels of password validation policy:
LOW Length >= 8
MEDIUM Length >= 8, numeric, mixed case, and special characters
STRONG Length >= 8, numeric, mixed case, special characters and dictionary file
Please enter 0 = LOW, 1 = MEDIUM and 2 = STRONG: 1接下来,您将收到提示以删除匿名用户、限制 root 用户仅从本地机器访问、删除测试数据库并重新加载权限表。您应该对所有问题回答 y。
输出
Remove anonymous users? (Press y|Y for Yes, any other key for No): y
Success.
Normally, root should only be allowed to connect from
'localhost'. This ensures that someone cannot guess at
the root password from the network.
Disallow root login remotely? (Press y|Y for Yes, any other key for No): y
Success.
By default, MySQL comes with a database named 'test' that
anyone can access. This is also intended only for testing,
and should be removed before moving into a production
environment.
Remove test database and access to it? (Press y|Y for Yes, any other key for No): y
- Dropping test database...
Success.
- Removing privileges on test database...
Success.
Reloading the privilege tables will ensure that all changes
made so far will take effect immediately.
Reload privilege tables now? (Press y|Y for Yes, any other key for No): y
Success.
All done! 以 root 身份登录
您可以使用 MySQL 客户端工具从命令行与 MySQL 服务器交互,该工具作为 MySQL 服务器软件包的依赖项安装。
在 MySQL 8.0 上,root 用户默认通过 auth_socket 插件进行身份验证。
auth_socket 插件对通过 Unix socket 文件从 localhost 连接的用户进行身份验证。这意味着您无法通过提供密码来以 root 身份进行身份验证。
要以 root 用户身份登录到 MySQL 服务器,请输入:
终端
sudo mysql您将看到如下所示的 MySQL shell:
输出
Welcome to the MySQL monitor. Commands end with; or \g.
Your MySQL connection id is 10
Server version: 8.0.35-0ubuntu0.22.04.1 (Ubuntu)
Copyright (c) 2000, 2023, Oracle and/or its affiliates.
Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
mysql> 如果您想使用外部程序(如 phpMyAdmin)以 root 身份登录到 MySQL 服务器,您有两个选项。
第一个选项是将身份验证方法从 auth_socket 更改为 mysql_native_password。您可以通过运行以下命令来做到这一点:
终端
ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'very_strong_password';
FLUSH PRIVILEGES;第二个推荐的选项是创建一个具有所有数据库访问权限的新专用管理用户:
终端
GRANT ALL PRIVILEGES ON *.* TO 'administrator'@'localhost' IDENTIFIED BY 'very_strong_password';