在Ubuntu上保障MySQL安全需要从多个方面进行配置和管理。以下是一些关键步骤和建议:
sudo apt update
sudo apt install mysql-server
sudo apt update
sudo apt upgrade mysql-server
设置强密码:在安装过程中或之后,设置一个强密码,并定期更换。
删除匿名用户:删除匿名用户,防止未经授权的访问。
sudo mysql_secure_installation
UPDATE mysql.user SET Host='localhost' WHERE User='root';
FLUSH PRIVILEGES;
CREATE USER 'username'@'localhost' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON *.* TO 'username'@'localhost';
FLUSH PRIVILEGES;
CREATE USER 'newuser'@'localhost' IDENTIFIED BY 'newpassword';
GRANT SELECT, INSERT ON mydatabase.* TO 'newuser'@'localhost';
FLUSH PRIVILEGES;
ufw
)限制对MySQL端口的访问。sudo ufw allow 3306/tcp
log_bin = /var/log/mysql/mysql-bin.log
mysqldump
等工具定期备份数据库。mysqldump -u root -p mydatabase > mydatabase_backup.sql
my.cnf
)中禁用不必要的功能,如local-infile
。[mysqld]
local-infile=0
SET GLOBAL validate_password.policy=MEDIUM;
SET GLOBAL validate_password.length=12;
通过以上步骤,可以显著提高Ubuntu上MySQL数据库的安全性,保护数据免受未授权访问和潜在的安全威胁。