数据库报错Tue Jun 28 15:45:42 CST 2022 WARN: Establishing SSL connection without server‘s identity verifi

Tue Jun 28 15:45:42 CST 2022 WARN: Establishing SSL connection without server's identity verification is not recommended. According to MySQL 5.5.45+, 5.6.26+ and 5.7.6+ requirements SSL connection must be established by default if explicit option isn't set. For compliance with existing applications not using SSL the verifyServerCertificate property is set to 'false'. You need either to explicitly disable SSL by setting useSSL=false, or set useSSL=true and provide truststore for server certificate verification.
 

MySQL5.7默认开启SSL加密连接,但是我的版本是5.5所以只能手动改一下

操作不了数据库得再pom.xml里面配置

 <properties>
        <maven.compiler.target>1.8</maven.compiler.target>
        <maven.compiler.source>1.8</maven.compiler.source>
        <junit.version>5.7.0</junit.version>
    </properties>
    private static final String DATABASE_URL = "jdbc:mysql://localhost:3306/db_news?characterEncoding=UTF8&useUnicode=true&useSSL=false&allowPublicKeyRetrieval=true";// 连接url地址


//在其问号后面加上characterEncoding=UTF8&useUnicode=true&useSSL=false&allowPublicKeyRetrieval=true

The message you're referring to is a warning in the MySQL logs, specifically related to establishing an SSL (Secure Sockets Layer) connection without verifying the server's identity. Here's what it means: When you connect to a MySQL server using SSL, it's important to ensure that you are connecting to a trusted server and not an imposter. The warning "Establishing SSL connection without server's identity verification is not recommended" indicates that the client is attempting to establish a secure connection but isn't verifying the authenticity of the server certificate. This could potentially expose your data to man-in-the-middle attacks. The reasons for this warning are: 1. Security: Verifying the server's identity ensures that you're connecting to the correct database and not an attacker masquerading as the server. It prevents unauthorized access or eavesdropping. 2. Data Integrity: SSL encryption also provides integrity, meaning that data exchanged between the client and server cannot be tampered with if the certificate is genuine. To address this warning, you should consider these options: - Obtain and install the server's trusted certificate, if it's missing or out of date. - Use SSL/TLS configuration settings that enforce client authentication, so both client and server certificates need to be validated. - Relax the security settings only when connecting to a trusted development or internal network where such verification is unnecessary. Here are some related questions: 1. What is SSL/TLS and why is it used in MySQL connections? 2. How can I obtain and install a server certificate for my MySQL setup? 3. What are the consequences of ignoring SSL warnings during database interactions?
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值