MySQL 8.0.28 Access Denied for users created with REQUIRE cipher '...'

Viewed 55

I am attempting to require specific SSL ciphers for users that I create in MySQL following this documentation but whenever I try to connect I get Access Denied. My steps are as follows

  1. Start MySQL (docker run --name mysql -p 3306 -e MYSQL_ROOT_PASSWORD=root mysql:8.0.28)
  2. Connect as root (mysql -u root -p -h 127.0.0.1 --port mapped_port)
  3. Create a user with a required cipher (CREATE USER 'user'@'%' identified by 'root' require cipher 'ECDHE-RSA-AES128-GCM-SHA256';)
  4. Attempt to connect as user (mysql -u user -h 127.0.0.1 --port mapped_port -p --ssl-cipher=ECDHE-RSA-AES128-GCM-SHA256 --tls-version=TLSv1.2)

If I attempt to connect with a different cipher I see an exception in the MySQL general log that indicates a cipher mismatch

2022-06-23T11:54:23.432986Z 16 [Note] [MY-010289] [Server] X.509 ciphers mismatch: should be 'ECDHE-RSA-AES128-GCM-SHA256' but is 'ECDHE-RSA-AES256-GCM-SHA384' 2022-06-23T11:54:23.433052Z 16 [Note] [MY-010926] [Server] Access denied for user 'user'@'127.0.0.1' (using password: YES)

but if I connect with the correct cipher I get only get the Access denied

2022-06-23T11:55:41.431244Z 17 [Note] [MY-010926] [Server] Access denied for user 'user'@'127.0.0.1' (using password: YES)

What am I missing that needs to be configured to enable requiring specific ciphers for connections?

0 Answers
Related