[ale] mySQL

Mike Lockhart backpacker at hikers.net
Thu Sep 19 16:37:46 EDT 2002


bash$# mysql -u root

mysql> create database databasename;

You specify InnoDB when you create the tables.

I would higly recommend using phpMyadmin if you're new to mysql, you can
look at the sql syntax and learn how it works (since there are a lot of
things specific to mysql that you don't find in postgres, oracle..)

Also, try this script that I've attached, written by one of the MySQL AB
guys who came to our company and trained us. (its a mysql secure script)

- mike

On Thu, 2002-09-19 at 15:27, ChangingLINKS.com wrote:
> 09-19-02 1512
> Boy, am I lost. I have been RTFM and trying to follow it, but I can't "do" 
> much yet. The good news is that when I type "mysql" at the command prompt, I 
> do get the "mysql>" The manual neglects rpm installation tips somewhat (like 
> where the mysql install directory "is"). 
> So, I go to /usr/bin and enter mysql_install_db. According to the manual, I 
> think I am supposed to get 6 new tables to appear in /var/lib/mysql. not.
> 
> And, when I do simple things, I get errors:
> 
> mysql> use mysql
> ERROR 1044: Access denied for user: '@localhost' to database 'mysql'
> 
> mysql> create database;
> ERROR 1064: You have an error in your SQL syntax near '' at line 1
> 
> Also, I am hoping that have InnoDb. How do I check to see if I do? I guess 
> that if I don't have InnoDb, it will be best to uninstall mySQL altogther and 
> start from scratch?
> -- 
> Wishing you Happiness, Joy and Laughter,
> Drew Brown
> http://www.ChangingLINKS.com
> 
> ---
> This message has been sent through the ALE general discussion list.
> See http://www.ale.org/mailing-lists.shtml for more info. Problems should be 
> sent to listmaster at ale dot org.
> 
-- 

================================
Michael Lockhart - PHP Developer
Intercosmos Media Group
mailto:mlockhart at intercosmos.com
http://orbital.intercosmos.net
================================


#!/bin/bash

# Copyright (C) 2002 MySQL AB and Jeremy Cole
# 
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
# 
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.
# 
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA

config=".my.cnf.$$"
command=".mysql.$$"

rootpass=""

prepare() {
    touch $config $command
    chmod 600 $config $command
}

do_query() {
    echo $1 >$command
    mysql --defaults-file=$config <$command
    return $?
}

make_config() {
    echo "# mysql_secure_installation config file" >$config
    echo "[mysql]" >>$config
    echo "user=root" >>$config
    echo "password=$rootpass" >>$config
}

get_root_password() {
    status=1
    while [ $status -eq 1 ]; do
	stty -echo
	echo -n "Enter current password for root (enter for none): "
	read password
	echo
	stty echo
	if [ "x$password" = "x" ]; then
	    hadpass=0
	else
	    hadpass=1
	fi
	rootpass=$password
	make_config
	do_query ""
	status=$?
    done
    echo "OK, successfully used password, moving on..."
    echo
}

set_root_password() {
    stty -echo
    echo -n "New password: "
    read password1
    echo
    echo -n "Re-enter new password: "
    read password2
    echo
    stty echo

    if [ "$password1" != "$password2" ]; then
	echo "Sorry, passwords do not match."
	echo
	return 1
    fi

    if [ "$password1" = "" ]; then
	echo "Sorry, you can't use an empty password here."
	echo
	return 1
    fi

    do_query "SET PASSWORD FOR root=PASSWORD('$password1');"
    if [ $? -eq 0 ]; then
	echo "Password updated successfully!"
	echo
	rootpass=$password1
	make_config
    else
	echo "Password update failed!"
	exit 1
    fi

    return 0
}

remove_anonymous_users() {
    do_query "DELETE FROM mysql.user WHERE User='';"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!"
	exit 1
    fi

    return 0
}

remove_remote_root() {
    do_query "DELETE FROM mysql.user WHERE User='root' AND Host!='localhost';"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!"
    fi
}

remove_test_database() {
    echo " - Dropping test database..."
    do_query "DROP DATABASE test;"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!  Not critical, keep moving..."
    fi

    echo " - Removing privileges on test database..."
    do_query "DELETE FROM mysql.db WHERE Db='test' OR Db='test\\_%'"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!  Not critical, keep moving..."
    fi

    return 0
}

reload_privilege_tables() {
    do_query "FLUSH PRIVILEGES;"
    if [ $? -eq 0 ]; then
	echo " ... Success!"
    else
	echo " ... Failed!"
    fi

    return 0
}

cleanup() {
    rm -f $config $command
}


# The actual script starts here

prepare

echo
echo
echo
echo
echo "NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MySQL"
echo "      SERVERS IN PRODUCTION USE!  PLEASE READ EACH STEP CAREFULLY!"
echo
echo

echo "In order to log into MySQL to secure it, we'll need the current"
echo "password for the root user.  If you've just installed MySQL, and"
echo "you haven't set the root password yet, the password will be blank,"
echo "so you should just press enter here."
echo

get_root_password


#
# Set the root password
#

echo "Setting the root password ensures that nobody can log into the MySQL"
echo "root user without the proper authorisation."
echo

if [ $hadpass -eq 0 ]; then
    echo -n "Set root password? [Y/n] "
else
    echo "You already have a root password set, so you can safely answer 'n'."
    echo
    echo -n "Change the root password? [Y/n] "
fi

read reply
if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    status=1
    while [ $status -eq 1 ]; do
	set_root_password
	status=$?
    done
fi
echo


#
# Remove anonymous users
#

echo "By default, a MySQL installation has an anonymous user, allowing anyone"
echo "to log into MySQL without having to have a user account created for"
echo "them.  This is intended only for testing, and to make the installation"
echo "go a bit smoother.  You should remove them before moving into a"
echo "production environment."
echo

echo -n "Remove anonymous users? [Y/n] "

read reply
if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    remove_anonymous_users
fi
echo


#
# Disallow remote root login
#

echo "Normally, root should only be allowed to connect from 'localhost'.  This"
echo "ensures that someone cannot guess at the root password from the network."
echo

echo -n "Disallow root login remotely? [Y/n] "
read reply
if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    remove_remote_root
fi
echo


#
# Remove test database
#

echo "By default, MySQL comes with a database named 'test' that anyone can"
echo "access.  This is also intended only for testing, and should be removed"
echo "before moving into a production environment."
echo

echo -n "Remove test database and access to it? [Y/n] "
read reply
if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    remove_test_database
fi
echo


#
# Reload privilege tables
#

echo "Reloading the privilege tables will ensure that all changes made so far"
echo "will take effect immediately."
echo

echo -n "Reload privilege tables now? [Y/n] "
read reply
if [ "$reply" = "n" ]; then
    echo " ... skipping."
else
    reload_privilege_tables
fi
echo

echo
echo
echo
echo "All done!  If you've completed all of the above steps, your MySQL"
echo "installation should now be secure."
echo
echo "Thanks for using MySQL!"
echo
echo

cleanup

 This is a digitally signed message part




More information about the Ale mailing list