模塊名 | 可用加密算法 | 密鑰長度限制 |
---|---|---|
keyring_encrypted_file | AES DSA RSA |
無限制 無限制 無限制 |
keyring_file | AES DSA RSA |
無限制 無限制 無限制 |
keyring_okv | AES | 16, 24, 32 |
keyring_aws | AES | 16, 24, 32 |
總結一下,四種方案都是文件加密,內存解密方案,區別在于加解密的key存放方案。推薦使用keyring_okv和keyring_aws,并確保mysql賬戶的安全性和嚴格區分賬戶權限。
另外2種安全性不大。
實施步驟
OK,現在簡單講一下最簡單的keyring_file部署方案,提前說明下windows貌似無法使用這種方案,因為不知道為什么加密用的key總是無法生成。
1.使用最新版的mysql 5.7.21
使用yum apt 之類的工具安裝最新版的mysql 或者 下載源碼自行編譯安裝
sudo apt install mysql-5.7
2.啟用加密模塊
INSTALL PLUGIN keyring_file soname ‘keyring_file.so';
mysql> INSTALL PLUGIN keyring_file soname 'keyring_file.so'; Query OK, 0 rows affected (0.10 sec)
3.設置加密key存放路徑
set global keyring_file_data='/root/mysql-keyring/keyring';
mysql> set global keyring_file_data='/var/lib/mysql-keyring/keyring'; Query OK, 0 rows affected (0.00 sec)
4.永久啟用設置
上訴兩個步驟都是臨時的,重啟服務都會失效,我們把配置寫到配置文件里,確保重啟服務后也能生效
[mysqld] early-plugin-load=keyring_file.so keyring_file_data=/root/mysql-keyring/keyring
5.查看key的存放路徑
show global variables like ‘%keyring_file_data%';
mysql> show global variables like '%keyring_file_data%'; +-------------------+--------------------------------+ | Variable_name | Value | +-------------------+--------------------------------+ | keyring_file_data | /var/lib/mysql-keyring/keyring | +-------------------+--------------------------------+ 1 row in set (0.00 sec)
6.查看啟用的模塊
查看下keyring_file模塊是否已經被載入。
show plugins;
mysql> show plugins; +----------------------------+----------+--------------------+-----------------+---------+ | Name | Status | Type | Library | License | +----------------------------+----------+--------------------+-----------------+---------+ | binlog | ACTIVE | STORAGE ENGINE | NULL | GPL | | mysql_native_password | ACTIVE | AUTHENTICATION | NULL | GPL | | sha256_password | ACTIVE | AUTHENTICATION | NULL | GPL | | PERFORMANCE_SCHEMA | ACTIVE | STORAGE ENGINE | NULL | GPL | | CSV | ACTIVE | STORAGE ENGINE | NULL | GPL | | MRG_MYISAM | ACTIVE | STORAGE ENGINE | NULL | GPL | | MyISAM | ACTIVE | STORAGE ENGINE | NULL | GPL | | InnoDB | ACTIVE | STORAGE ENGINE | NULL | GPL | | INNODB_TRX | ACTIVE | INFORMATION SCHEMA | NULL | GPL | | INNODB_LOCKS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | | INNODB_LOCK_WAITS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | | INNODB_CMP | ACTIVE | INFORMATION SCHEMA | NULL | GPL | | INNODB_CMP_RESET | ACTIVE | INFORMATION SCHEMA | NULL | GPL | 。。。。。。(省略N條) | keyring_file | ACTIVE | KEYRING | keyring_file.so | GPL | +----------------------------+----------+--------------------+-----------------+---------+ 45 rows in set (0.00 sec)
7.加密現有的表
alter table table encryption='Y';
mysql> create table cc (id int); Query OK, 0 rows affected (0.01 sec) mysql> alter table cc encryption='Y'; Query OK, 0 rows affected (0.06 sec) Records: 0 Duplicates: 0 Warnings: 0
8.取消加密
alter table table encryption='N';
mysql> alter table cc encryption='N'; Query OK, 0 rows affected (0.01 sec) Records: 0 Duplicates: 0 Warnings: 0
官方文檔:
https://dev.mysql.com/doc/refman/5.7/en/keyring-installation.html
以上就是本文的全部內容,希望對大家的學習有所幫助,也希望大家多多支持腳本之家。