LINUXOR.SK ... open source notes ...

Email - MariaDB my.cnf, webmail

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Webmail

The main configuration file of the MariaDB server behind Roundcube. It is the file the package installed, unchanged: data directory, socket and the include of /etc/my.cnf.d. The one change I made is in an included file and is in the table after the fence.

ItemValue
Path on the server/etc/my.cnf
Shown hereDC2-A-VCMSX002
SoftwareMariaDB 5.5 from RHEL 7 (mariadb-server)
Socket/var/lib/mysql/mysql.sock
Activated withsystemctl start mariadb and systemctl enable mariadb in the install notes

The file

ini
[mysqld]
datadir=/var/lib/mysql
socket=/var/lib/mysql/mysql.sock
# Disabling symbolic-links is recommended to prevent assorted security risks
symbolic-links=0
# Settings user and group are ignored when systemd is used.
# If you need to run mysqld under a different user or group,
# customize your systemd unit file for mariadb according to the
# instructions in http://fedoraproject.org/wiki/Systemd

[mysqld_safe]
log-error=/var/log/mariadb/mariadb.log
pid-file=/var/run/mariadb/mariadb.pid

#
# include all files from the config directory
#
!includedir /etc/my.cnf.d

The files under my.cnf.d

FileState
/etc/my.cnf.d/client.cnfstock, only empty groups
/etc/my.cnf.d/mysql-clients.cnfstock, only empty groups
/etc/my.cnf.d/server.cnfstock, plus skip-networking in the groups [mariadb] and [mariadb-5.5], each under the comment # CFG-ON -> skip-networking

With skip-networking the server opens no TCP port at all, and the Unix socket is the only way in. The design document names server.cnf as the main configuration file of MariaDB for that reason.

Checked against MariaDB 11.8

As builtToday
MariaDB 5.5End of life since 2020-04-11. Long-term series today are 10.11, 11.4, 11.8 and 12.3; RHEL 10 ships 10.11, and 11.8 since RHEL 10.2
mysql_secure_installationThe tool is now mariadb-secure-installation; the old name remains as a symlink
A password for root set by that toolroot@localhost uses the unix_socket authentication plugin by default, and there is usually no need to create a root password
Group [mariadb-5.5] in server.cnfA version-specific group. I expect that a server of another version does not read it; the research could not verify that

I did not re-check skip-networking against the current server documentation.

← solutionz