FM

//bin UP

#!/bin/sh

# Copyright (c) 2002, 2016, Oracle and/or its affiliates. All rights reserved.
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; version 2 of the License.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1335  USA

config=".my.cnf.$$"
command=".mysql.$$"
output=".my.output.$$"

trap "interrupt" 1 2 3 6 15

rootpass=""
echo_n=
echo_c=
basedir=
defaults_file=
defaults_extra_file=
defaults_group_suffix=
no_defaults=

case "$0" in
  *mysql_secure_installation)
    echo "$0: Deprecated program name. It will be removed in a future release, use 'mariadb-secure-installation' instead" 1>&2
    ;;
esac

parse_arg()
{
  echo "$1" | sed -e 's/^[^=]*=//'
}

parse_arguments()
{
  # We only need to pass arguments through to the server if we don't
  # handle them here.  So, we collect unrecognized options (passed on
  # the command line) into the args variable.
  pick_args=
  if test "$1" = PICK-ARGS-FROM-ARGV
  then
    pick_args=1
    shift
  fi

  for arg
  do
    case "$arg" in
      --basedir=*) basedir=`parse_arg "$arg"` ;;
      --defaults-file=*) defaults_file="$arg" ;;
      --defaults-extra-file=*) defaults_extra_file="$arg" ;;
      --defaults-group-suffix=*) defaults_group_suffix="$arg" ;;
      --no-defaults) no_defaults="$arg" ;;
      *)
        if test -n "$pick_args"
        then
          # This sed command makes sure that any special chars are quoted,
          # so the arg gets passed exactly to the server.
          # XXX: This is broken; true fix requires using eval and proper
          # quoting of every single arg ($basedir, $ldata, etc.)
          #args="$args "`echo "$arg" | sed -e 's,\([^a-zA-Z0-9_.-]\),\\\\\1,g'`
          args="$args $arg"
        fi
        ;;
    esac
  done
}

# Try to find a specific file within --basedir which can either be a binary
# release or installed source directory and return the path.
find_in_basedir()
{
  return_dir=0
  found=0
  case "$1" in
    --dir)
      return_dir=1; shift
      ;;
  esac

  file=$1; shift

  for dir in "$@"
  do
    if test -f "$basedir/$dir/$file"
    then
      found=1
      if test $return_dir -eq 1
      then
        echo "$basedir/$dir"
      else
        echo "$basedir/$dir/$file"
      fi
      break
    fi
  done

  if test $found -eq 0
  then
      # Test if command is in PATH
      $file --no-defaults --version > /dev/null 2>&1
      status=$?
      if test $status -eq 0
      then
        echo $file
      fi
  fi
}

cannot_find_file()
{
  echo
  echo "FATAL ERROR: Could not find $1"

  shift
  if test $# -ne 0
  then
    echo
    echo "The following directories were searched:"
    echo
    for dir in "$@"
    do
      echo "    $dir"
    done
  fi

  echo
  echo "If you compiled from source, you need to run 'make install' to"
  echo "copy the software into the correct location ready for operation."
  echo
  echo "If you are using a binary release, you must either be at the top"
  echo "level of the extracted archive, or pass the --basedir option"
  echo "pointing to that location."
  echo
}

# Ok, let's go.  We first need to parse arguments which are required by
# my_print_defaults so that we can execute it first, then later re-parse
# the command line to add any extra bits that we need.
parse_arguments PICK-ARGS-FROM-ARGV "$@"

#
# We can now find my_print_defaults.  This script supports:
#
#   --srcdir=path pointing to compiled source tree
#   --basedir=path pointing to installed binary location
#
# or default to compiled-in locations.
#

if test -n "$basedir"
then
  print_defaults=`find_in_basedir my_print_defaults bin extra`
  echo "print: $print_defaults"
  if test -z "$print_defaults"
  then
    cannot_find_file my_print_defaults $basedir/bin $basedir/extra
    exit 1
  fi
  mysql_command=`find_in_basedir mariadb bin`
  if test -z "$mysql_command"
  then
      cannot_find_file mariadb $basedir/bin
      exit 1
  fi
else
  print_defaults="/usr/bin/my_print_defaults"
  mysql_command="/usr/bin/mariadb"
fi

if test ! -x "$print_defaults"
then
  cannot_find_file "$print_defaults"
  exit 1
fi

if test ! -x "$mysql_command"
then
  cannot_find_file "$mysql_command"
  exit 1
fi

# Now we can get arguments from the group [client] and [client-server]
# in the my.cfg file, then re-run to merge with command line arguments.
parse_arguments `$print_defaults $defaults_file $defaults_extra_file $defaults_group_suffix $no_defaults client client-server client-mariadb`
parse_arguments PICK-ARGS-FROM-ARGV "$@"

set_echo_compat() {
    case `echo "testing\c"`,`echo -n testing` in
	*c*,-n*) echo_n=   echo_c=     ;;
	*c*,*)   echo_n=-n echo_c=     ;;
	*)       echo_n=   echo_c='\c' ;;
    esac
}

validate_reply () {
    ret=0
    if [ -z "$1" ]; then
	reply=y
	return $ret
    fi
    case $1 in
        y|Y|yes|Yes|YES) reply=y ;;
        n|N|no|No|NO)    reply=n ;;
        *) ret=1 ;;
    esac
    return $ret
}

prepare() {
    umask 0077
    touch $config $command $output
}

do_query() {
    echo "$1" >$command
    #sed 's,^,> ,' < $command  # Debugging
    $mysql_command --defaults-file=$config $defaults_extra_file $no_defaults $args <$command >$output
    return $?
}

# Simple escape mechanism (\-escape any ' and \), suitable for two contexts:
# - single-quoted SQL strings
# - single-quoted option values on the right hand side of = in my.cnf
#
# These two contexts don't handle escapes identically.  SQL strings allow
# quoting any character (\C => C, for any C), but my.cnf parsing allows
# quoting only \, ' or ".  For example, password='a\b' quotes a 3-character
# string in my.cnf, but a 2-character string in SQL.
#
# This simple escape works correctly in both places.
basic_single_escape () {
    # The quoting on this sed command is a bit complex.  Single-quoted strings
    # don't allow *any* escape mechanism, so they cannot contain a single
    # quote.  The string sed gets (as argv[1]) is:  s/\(['\]\)/\\\1/g
    #
    # Inside a character class, \ and ' are not special, so the ['\] character
    # class is balanced and contains two characters.
    echo "$1" | sed 's/\(['"'"'\]\)/\\\1/g'
}

#
# create a simple my.cnf file to be able to pass the root password to the mysql
# client without putting it on the command line
#
make_config() {
    echo "# mysql_secure_installation config file" >$config
    echo "[mysql]" >>$config
    echo "user=root" >>$config
    esc_pass=`basic_single_escape "$rootpass"`
    echo "password='$esc_pass'" >>$config
    #sed 's,^,> ,' < $config  # Debugging

    if test -n "$defaults_file"
    then
        dfile=`parse_arg "$defaults_file"`
        cat "$dfile" >>$config
    fi
}

get_root_password() {
    status=1
    while [ $status -eq 1 ]; do
	stty -echo
	echo $echo_n "Enter current password for root (enter for none): $echo_c"
	read password
	echo
	stty echo
	if [ "x$password" = "x" ]; then
	    emptypass=1
	else
	    emptypass=0
	fi
	rootpass=$password
	make_config
	do_query "show create user root@localhost"
	status=$?
    done
    if grep -q unix_socket $output; then
      emptypass=0
    fi
    echo "OK, successfully used password, moving on..."
    echo
}

set_root_password() {
    stty -echo
    echo $echo_n "New password: $echo_c"
    read password1
    echo
    echo $echo_n "Re-enter new password: $echo_c"
    read password2
    echo
    stty echo

    if [ "$password1" != "$password2" ]; then
	echo "Sorry, passwords do not match."
	echo
	return 1
    fi

    if [ "$password1" = "" ]; then
	echo "Sorry, you can't use an empty password here."
	echo
	return 1
    fi

    esc_pass=`basic_single_escape "$password1"`
    do_query "UPDATE mysql.global_priv SET priv=json_set(priv, '$.plugin', 'mysql_native_password', '$.authentication_string', PASSWORD('$esc_pass')) WHERE User='root';"
    if [ $? -eq 0 ]; then
	echo "Password updated successfully!"
	echo "Reloading privilege tables.."
	reload_privilege_tables
	if [ $? -eq 1 ]; then
		clean_and_exit
	fi
	echo
	rootpass=$password1
	make_config
    else
	echo "Password update failed!"
	clean_and_exit
    fi

    return 0
}

remove_anonymous_users() {
    do_query "DELETE FROM mysql.global_priv WHERE User='';"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!"
	clean_and_exit
    fi

    return 0
}

remove_remote_root() {
    do_query "DELETE FROM mysql.global_priv WHERE User='root' AND Host NOT IN ('localhost', '127.0.0.1', '::1');"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!"
    fi
}

remove_test_database() {
    echo " - Dropping test database..."
    do_query "DROP DATABASE IF EXISTS test;"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!  Not critical, keep moving..."
    fi

    echo " - Removing privileges on test database..."
    do_query "DELETE FROM mysql.db WHERE Db='test' OR Db='test\\_%'"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!  Not critical, keep moving..."
    fi

    return 0
}

reload_privilege_tables() {
    do_query "FLUSH PRIVILEGES;"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
	return 0
    else
	echo " ... Failed!"
	return 1
    fi
}

interrupt() {
    echo
    echo "Aborting!"
    echo
    cleanup
    stty echo
    exit 1
}

cleanup() {
    echo "Cleaning up..."
    rm -f $config $command $output
}

# Remove the files before exiting.
clean_and_exit() {
	cleanup
	exit 1
}

# The actual script starts here

prepare
set_echo_compat

echo
echo "NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MariaDB"
echo "      SERVERS IN PRODUCTION USE!  PLEASE READ EACH STEP CAREFULLY!"
echo
echo "In order to log into MariaDB to secure it, we'll need the current"
echo "password for the root user. If you've just installed MariaDB, and"
echo "haven't set the root password yet, you should just press enter here."
echo

get_root_password


#
# Set the root password
#

echo "Setting the root password or using the unix_socket ensures that nobody"
echo "can log into the MariaDB root user without the proper authorisation."
echo

while true ; do
    if [ $emptypass -eq 1 ]; then
	echo $echo_n "Enable unix_socket authentication? [Y/n] $echo_c"
    else
	echo "You already have your root account protected, so you can safely answer 'n'."
	echo
	echo $echo_n "Switch to unix_socket authentication [Y/n] $echo_c"
    fi
    read reply
    validate_reply $reply && break
done

if [ "$reply" = "n" ]; then
  echo " ... skipping."
else
  emptypass=0
  do_query "UPDATE mysql.global_priv SET priv=json_set(priv, '$.password_last_changed', UNIX_TIMESTAMP(), '$.plugin', 'mysql_native_password', '$.authentication_string', 'invalid', '$.auth_or', json_array(json_object(), json_object('plugin', 'unix_socket'))) WHERE User='root';"
  if [ $? -eq 0 ]; then
   echo "Enabled successfully!"
   echo "Reloading privilege tables.."
   reload_privilege_tables
   if [ $? -eq 1 ]; then
     clean_and_exit
   fi
   echo
  else
   echo "Failed!"
   clean_and_exit
  fi
fi
echo

while true ; do
    if [ $emptypass -eq 1 ]; then
	echo $echo_n "Set root password? [Y/n] $echo_c"
    else
	echo "You already have your root account protected, so you can safely answer 'n'."
	echo
	echo $echo_n "Change the root password? [Y/n] $echo_c"
    fi
    read reply
    validate_reply $reply && break
done

if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    status=1
    while [ $status -eq 1 ]; do
	set_root_password
	status=$?
    done
fi
echo


#
# Remove anonymous users
#

echo "By default, a MariaDB installation has an anonymous user, allowing anyone"
echo "to log into MariaDB without having to have a user account created for"
echo "them.  This is intended only for testing, and to make the installation"
echo "go a bit smoother.  You should remove them before moving into a"
echo "production environment."
echo

while true ; do
    echo $echo_n "Remove anonymous users? [Y/n] $echo_c"
    read reply
    validate_reply $reply && break
done
if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    remove_anonymous_users
fi
echo


#
# Disallow remote root login
#

echo "Normally, root should only be allowed to connect from 'localhost'.  This"
echo "ensures that someone cannot guess at the root password from the network."
echo
while true ; do
    echo $echo_n "Disallow root login remotely? [Y/n] $echo_c"
    read reply
    validate_reply $reply && break
done
if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    remove_remote_root
fi
echo


#
# Remove test database
#

echo "By default, MariaDB comes with a database named 'test' that anyone can"
echo "access.  This is also intended only for testing, and should be removed"
echo "before moving into a production environment."
echo

while true ; do
    echo $echo_n "Remove test database and access to it? [Y/n] $echo_c"
    read reply
    validate_reply $reply && break
done

if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    remove_test_database
fi
echo


#
# Reload privilege tables
#

echo "Reloading the privilege tables will ensure that all changes made so far"
echo "will take effect immediately."
echo

while true ; do
    echo $echo_n "Reload privilege tables now? [Y/n] $echo_c"
    read reply
    validate_reply $reply && break
done

if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    reload_privilege_tables
fi
echo

cleanup

echo
echo "All done!  If you've completed all of the above steps, your MariaDB"
echo "installation should now be secure."
echo
echo "Thanks for using MariaDB!"
7za46V
[54888V
aclocal36478V
aclocal-1.1636478V
addr2line34224V
ar63448V
arch38232V
arpaname12104V
as911264V
aspell163328V
autoconf14768V
autoheader8534V
autom4te32181V
automake257949V
automake-1.16257949V
autoreconf21066V
autoscan17124V
autoupdate33872V
awk685848V
b2sum59072V
base3242464V
base6442480V
basename38312V
bash1154680V
bashbug-647348V
bun92752752V
bunzip237744V
bzcat37744V
bzcmp2128V
bzdiff2128V
bzgrep1677V
bzip237744V
bzip2recover16832V
bzless1259V
bzmore1259V
c++1266616V
c++filt29584V
cagefs_enter.proxied1296V
cal67560V
captoinfo87360V
cat38360V
catchsegv3283V
cc-
chcon72032V
chgrp67880V
chmod63688V
chown71976V
chrt38080V
cksum38288V
clear12840V
cloudlinux-awp-user1818V
clwpos-user1818V
cmp106248V
col29704V
colcrt16872V
colrm25480V
column50656V
comm42560V
cp151528V
cpp1266552V
csplit54968V
curl235600V
cut50704V
date108504V
dbiprof6206V
delv43480V
df93272V
diff274440V
diff3131688V
dig166072V
dir143256V
dircolors50744V
dirname34160V
dltest12152V
dnstap-read20920V
du109568V
easy_install-3-
echo38248V
egrep28V
enchant21584V
enchant-lsmod13408V
env42344V
eps2eps639V
eqn237728V
ex1180432V
expand42592V
expr50760V
factor88032V
false34120V
fc-cache132V
fc-cache-6420840V
fc-cat16744V
fc-conflist12544V
fc-list12544V
fc-match16648V
fc-pattern12552V
fc-query12536V
fc-scan12552V
fc-validate16648V
fgrep28V
file25280V
find228632V
flock33992V
fmt46584V
fold42416V
free21288V
funzip37504V
g++1266616V
gawk685848V
gcc-ar37536V
gcc-nm37536V
gcc-ranlib37536V
gcov-dump584664V
gcov-tool622360V
gencat25432V
geoiplookup22416V
geoiplookup622168V
geqn237728V
getconf33240V
getent33920V
getopt21024V
ghostscript12648V
gifdiff63384V
gifsicle205056V
git3845928V
git-receive-pack3845928V
git-shell2236688V
git-upload-archive3845928V
git-upload-pack3845928V
gm8008V
gneqn908V
gnroff3312V
gpg1090344V
gpg-agent429360V
gpg-error34976V
gpg-zip3525V
gpgsplit89112V
gpgv462344V
gpic300896V
gprof105832V
grep198280V
groff127920V
grops195728V
grotty145304V
groups38288V
gs12648V
gsnd277V
gsoelim43576V
gtar459768V
gtbl158320V
gtroff824344V
gunzip2345V
gzexe6375V
gzip96944V
hdu18520V
head46592V
hexdump58888V
host145704V
hostid34136V
hostname21664V
hunspell148168V
iconv62904V
id46528V
idn40352V
ifnames4128V
infocmp62512V
infotocap87360V
install159912V
ionice29680V
ipcrm29688V
ipcs54680V
isosize25480V
ispell988V
isql37456V
iusql29344V
join54984V
jpegoptim40000V
kill38176V
ld1789080V
ld.bfd1789080V
ldd5441V
less177928V
lessecho12696V
lesskey22520V
lesspipe.sh3143V
link34136V
ln72192V
locale57800V
localedef314848V
logger51184V
login41944V
logname34144V
look16856V
ls143264V
m4190016V
mailq-
make-dummy-cert610V
mariadb5320256V
mariadb-access112112V
mariadb-admin5087080V
mariadb-binlog5355944V
mariadb-check5084352V
mariadb-conv4800464V
mariadb-convert-table-format4385V
mariadb-dump5190624V
mariadb-dumpslow8382V
mariadb-embedded25370280V
mariadb-find-rows3433V
mariadb-hotcopy35497V
mariadb-import5198192V
mariadb-plugin4779336V
mariadb-secure-installation13982V
mariadb-setpermission18128V
mariadb-show5073480V
mariadb-slap5092920V
mariadb-tzinfo-to-sql4774552V
mariadb-waitpid4765944V
mc1360320V
mcdiff1360320V
mcedit1360320V
mcookie34064V
mcview1360320V
md5sum46632V
mesg16752V
mkdir84680V
mkfifo68056V
mknod72160V
mktemp46752V
more46016V
msmtp135208V
msmtpd21024V
msql2mysql1446V
mv147416V
my_print_defaults4766376V
mysql5320256V
mysql_config4574V
mysql_find_rows3433V
mysql_waitpid4765944V
mysqlaccess112112V
mysqladmin5087080V
mysqlbinlog5355944V
mysqlcheck5084352V
mysqldump5190624V
mysqlimport5198192V
mysqlshow5073480V
mytop73757V
namei33896V
nano253888V
neqn908V
newaliases-
nice38224V
nl46648V
nm51584V
nohup38312V
nproc38304V
nroff3312V
nslookup149768V
nsupdate74808V
numfmt67216V
objcopy245832V
objdump429832V
od75576V
odbc_config12128V
odbcinst29576V
openssl763856V
optipng145256V
pango-list12160V
pango-view58816V
passwd1284V
paste38296V
patch211416V
pathchk38232V
pdf2dsc698V
pdf2ps909V
perldoc118V
pgrep29536V
php6405720V
php-cgi6405192V
phpize5082V
pic300896V
piconv8271V
pinentry2404V
pinentry-curses79760V
ping67712V
pinky42456V
pip-3-
pip3-
pkill29536V
pmap33568V
pod2man15034V
pod2text10803V
pod2usage3948V
post-grohtml244456V
pr84120V
pre-grohtml133688V
precat5656V
preunzip5656V
prezip5656V
prezip-bin12264V
printenv34120V
printf54848V
ps137984V
ps2ascii631V
ps2epsi2752V
ps2pdf272V
ps2pdf12215V
ps2pdf13215V
ps2pdf14215V
ps2pdfwr1097V
ps2ps647V
ps2ps2669V
ptx79872V
pwd38320V
pwdx12984V
pydoc-3-
pydoc3-
python311872V
python3.611872V
python3.6m11872V
pyvenv-3-
ranlib63456V
raw16896V
readelf639528V
readlink46984V
realpath51136V
recode48160V
rename16896V
renew-dummy-cert725V
renice16856V
replace4744232V
reset25352V
restic29778104V
rev12760V
rm72064V
rmdir46552V
rnano253888V
rsync522376V
run-with-aspell85V
runcon38272V
rvi1180432V
rview1180432V
rvim3067856V
scalar2290912V
scl37752V
scl_enabled258V
scl_source1863V
scp108816V
script37680V
sdiff107856V
sed118248V
seq54728V
setsid16768V
setterm46208V
sftp162976V
sh1154680V
sha1sum46640V
sha224sum46672V
sha256sum46672V
sha384sum46688V
sha512sum46688V
shred63336V
shuf59488V
size34048V
skill29488V
slabtop21344V
sleep38296V
slencheck12584V
snice29488V
soelim43576V
sort126440V
spell122V
split59440V
sprof29360V
sqlite31346512V
ssh779208V
ssh-add353808V
ssh-agent332768V
ssh-copy-id10694V
ssh-keygen440896V
ssh-keyscan442304V
stat88232V
stdbuf50688V
strings38328V
strip245856V
stty79472V
sum46624V
svn346872V
svnadmin103376V
svndumpfilter37600V
svnfsfs41640V
svnlook78688V
svnrdump58408V
svnserve112288V
svnsync62512V
svnversion16696V
sync38248V
tabs16952V
tac42488V
tail75912V
tar459768V
taskset38152V
tbl158320V
tclsh9256V
tclsh8.69256V
tee42472V
test54832V
tic87360V
timeout42856V
tload17160V
tmpwatch36320V
toe16848V
top124616V
touch96192V
tput25392V
tr50816V
tree83544V
troff824344V
true34128V
truncate42352V
tset25352V
tsort42488V
tty34112V
tzselect15370V
ul21080V
uname38224V
unexpand46704V
uniq50832V
unlink34144V
unrar355344V
unversioned-python-
unzip206728V
unzipsfx103912V
uptime12888V
users38296V
utmpdump29352V
vdir143264V
vi1180432V
view1180432V
vim3067856V
vimdiff3067856V
vimtutor2121V
vmstat37672V
watch29888V
wc50832V
wget533928V
whereis29976V
which30088V
who54880V
whoami34136V
word-list-compress12280V
x86_64-redhat-linux-c++1266616V
x86_64-redhat-linux-g++1266616V
x86_64-redhat-linux-gcc-81266576V
xargs75888V
xmlcatalog20864V
xmllint75128V
xmlwf37848V
xsltproc29152V
xxd21032V
yes34168V
zcat1983V
zcmp1677V
zdiff5879V
zegrep29V
zfgrep29V
zforce2080V
zgrep7582V
zip234496V
zipcloak105376V
zipgrep2953V
zipinfo206728V
zipnote100104V
zipsplit100104V
zless2205V
zmore1841V
znew4552V
zsoelim43576V
Blog - My Melon - Digital Marketing & Creative Agency
Skip to content Skip to footer