SV-235154r638812_rule
V-235154
SRG-APP-000224-DB-000384
MYS8-00-007000
CAT II
10
Connect as a mysql administrator
mysql> set persist require_secure_transport=ON;
Turn on MySQL FIPS mode (ON or STRICT) and restart mysqld
Edit my.cnf
[mysqld]
ssl_fips_mode=ON
or
ssl_fips_mode=STRICT
Determine if MySQL is configured to require SSL.
SELECT VARIABLE_NAME, VARIABLE_VALUE
FROM performance_schema.global_variables
WHERE VARIABLE_NAME like 'require_secure_transport';
If require_secure_transport is not "ON", this is a finding.
Determine if MySQL is configured to require the use of FIPS compliant algorithms.
SELECT VARIABLE_NAME, VARIABLE_VALUE
FROM performance_schema.global_variables
WHERE VARIABLE_NAME = 'ssl_fips_mode';
If ssl_fips_mode is not "ON", this is a finding.
V-235154
False
MYS8-00-007000
Determine if MySQL is configured to require SSL.
SELECT VARIABLE_NAME, VARIABLE_VALUE
FROM performance_schema.global_variables
WHERE VARIABLE_NAME like 'require_secure_transport';
If require_secure_transport is not "ON", this is a finding.
Determine if MySQL is configured to require the use of FIPS compliant algorithms.
SELECT VARIABLE_NAME, VARIABLE_VALUE
FROM performance_schema.global_variables
WHERE VARIABLE_NAME = 'ssl_fips_mode';
If ssl_fips_mode is not "ON", this is a finding.
M
5277