Email - MariaDB my.cnf, webmail
Email Solution · Config document · referenced from Webmail
The main configuration file of the MariaDB server behind Roundcube. It is the file the package installed, unchanged: data directory, socket and the include of /etc/my.cnf.d. The one change I made is in an included file and is in the table after the fence.
| Item | Value |
|---|---|
| Path on the server | /etc/my.cnf |
| Shown here | DC2-A-VCMSX002 |
| Software | MariaDB 5.5 from RHEL 7 (mariadb-server) |
| Socket | /var/lib/mysql/mysql.sock |
| Activated with | systemctl start mariadb and systemctl enable mariadb in the install notes |
The file
[mysqld] datadir=/var/lib/mysql socket=/var/lib/mysql/mysql.sock # Disabling symbolic-links is recommended to prevent assorted security risks symbolic-links=0 # Settings user and group are ignored when systemd is used. # If you need to run mysqld under a different user or group, # customize your systemd unit file for mariadb according to the # instructions in http://fedoraproject.org/wiki/Systemd [mysqld_safe] log-error=/var/log/mariadb/mariadb.log pid-file=/var/run/mariadb/mariadb.pid # # include all files from the config directory # !includedir /etc/my.cnf.d
The files under my.cnf.d
| File | State |
|---|---|
/etc/my.cnf.d/client.cnf | stock, only empty groups |
/etc/my.cnf.d/mysql-clients.cnf | stock, only empty groups |
/etc/my.cnf.d/server.cnf | stock, plus skip-networking in the groups [mariadb] and [mariadb-5.5], each under the comment # CFG-ON -> skip-networking |
With skip-networking the server opens no TCP port at all, and the Unix socket is the only way in. The design document names server.cnf as the main configuration file of MariaDB for that reason.
Checked against MariaDB 11.8
| As built | Today |
|---|---|
| MariaDB 5.5 | End of life since 2020-04-11. Long-term series today are 10.11, 11.4, 11.8 and 12.3; RHEL 10 ships 10.11, and 11.8 since RHEL 10.2 |
mysql_secure_installation | The tool is now mariadb-secure-installation; the old name remains as a symlink |
A password for root set by that tool | root@localhost uses the unix_socket authentication plugin by default, and there is usually no need to create a root password |
Group [mariadb-5.5] in server.cnf | A version-specific group. I expect that a server of another version does not read it; the research could not verify that |
I did not re-check skip-networking against the current server documentation.