为了加强安全性,MySQL5.7为root⽤户随机⽣成了⼀个密码,在error log中,关于error log的位置,如果安装的是RPM包,则默认是/var/log/mysqld.log。⼀般可通过log_error设置
mysql> select @@log_error;+---------------------+
| @@log_error |+---------------------+| /var/log/mysqld.log |+---------------------+
1 row in set (0.00 sec)
可通过# grep \"password\" /var/log/mysqld.log 命令获取MySQL的临时密码
2016-01-19T05:16:36.218234Z 1 [Note] A temporary password is generated for root@localhost: waQ,qR%be2(5
⽤该密码登录到服务端后,必须马上修改密码,不然会报如下错误:
mysql> select user();
ERROR 1820 (HY000): You must reset your password using ALTER USER statement before executing this statement.
如果只是修改为⼀个简单的密码,会报以下错误:
mysql> ALTER USER USER() IDENTIFIED BY '12345678';
ERROR 1819 (HY000): Your password does not satisfy the current policy requirements
这个其实与validate_password_policy的值有关。validate_password_policy有以下取值:Policy
0 or LOW1 or MEDIUM2 or STRONG
Tests Performed
LengthLength; numeric, lowercase/uppercase, and special charactersLength; numeric, lowercase/uppercase, and special characters; dictionary file默认是1,即MEDIUM,所以刚开始设置的密码必须符合长度,且必须含有数字,⼩写或⼤写字母,特殊字符。有时候,只是为了⾃⼰测试,不想密码设置得那么复杂,譬如说,我只想设置root的密码为123456。必须修改两个全局参数:
⾸先,修改validate_password_policy参数的值
mysql> set global validate_password_policy=0;Query OK, 0 rows affected (0.00 sec)
这样,判断密码的标准就基于密码的长度了。这个由validate_password_length参数来决定。
mysql> select @@validate_password_length;+----------------------------+
| @@validate_password_length |+----------------------------+| 8 |+----------------------------+1 row in set (0.00 sec)
validate_password_length参数默认为8,它有最⼩值的限制,最⼩值为:
validate_password_number_count
+ validate_password_special_char_count+ (2 * validate_password_mixed_case_count)
其中,validate_password_number_count指定了密码中数据的长度,validate_password_special_char_count指定了密码中特殊字符的长度,validate_password_mixed_case_count指定了密码中⼤⼩字母的长度。
这些参数,默认值均为1,所以validate_password_length最⼩值为4,如果你显性指定validate_password_length的值⼩于4,尽管不会报错,但validate_password_length的值将设为4。如下所⽰:
mysql> select @@validate_password_length;+----------------------------+
| @@validate_password_length |+----------------------------+| 8 |
+----------------------------+1 row in set (0.00 sec)
mysql> set global validate_password_length=1;Query OK, 0 rows affected (0.00 sec)
mysql> select @@validate_password_length;+----------------------------+
| @@validate_password_length |+----------------------------+| 4 |+----------------------------+1 row in set (0.00 sec)
如果修改了validate_password_number_count,validate_password_special_char_count,validate_password_mixed_case_count中任何⼀个值,则validate_password_length将进⾏动态修改。
mysql> select @@validate_password_length;+----------------------------+
| @@validate_password_length |+----------------------------+| 4 |+----------------------------+1 row in set (0.00 sec)
mysql> select @@validate_password_mixed_case_count;+--------------------------------------+
| @@validate_password_mixed_case_count |+--------------------------------------+| 1 |+--------------------------------------+1 row in set (0.00 sec)
mysql> set global validate_password_mixed_case_count=2;Query OK, 0 rows affected (0.00 sec)
mysql> select @@validate_password_mixed_case_count;+--------------------------------------+
| @@validate_password_mixed_case_count |+--------------------------------------+| 2 |+--------------------------------------+1 row in set (0.00 sec)
mysql> select @@validate_password_length;+----------------------------+
| @@validate_password_length |+----------------------------+| 6 |+----------------------------+1 row in set (0.00 sec)
当然,前提是validate_password插件必须已经安装,MySQL5.7是默认安装的。
那么如何验证validate_password插件是否安装呢?可通过查看以下参数,如果没有安装,则输出将为空。
mysql> SHOW VARIABLES LIKE 'validate_password%';+--------------------------------------+-------+
| Variable_name | Value |+--------------------------------------+-------+
| validate_password_dictionary_file | || validate_password_length | 6 |
| validate_password_mixed_case_count | 2 || validate_password_number_count | 1 || validate_password_policy | LOW || validate_password_special_char_count | 1 |+--------------------------------------+-------+6 rows in set (0.00 sec)
因篇幅问题不能全部显示,请点此查看更多更全内容