donglugou6652 2018-10-24 06:07
浏览 832
已采纳

如何使用gorm创建与MySQL的SSL连接?

Can't seem to find any resource on creating a SSL connection to mysql using gorm. I am creating a non-ssl connection like this:

cfg := mysql.Config{
    User:   config.User,
    Passwd: config.Password,
    Addr:   fmt.Sprintf("%s:%d", config.Host, config.Port),
    Net:    "tcp",
    Params: options,
}

str := cfg.FormatDSN()
db, err := gorm.Open("mysql", str)

Passing 'ssl-ca' option in Param options with path to 'pem' file does not seem to work. Any heads up on this?

  • 写回答

1条回答 默认 最新

  • doushu5451 2019-01-16 17:25
    关注

    This is a fragment of my working code :

    isTLS := false
    
    if mysqlClientKey != "" && mysqlCaCert != ""  && mysqlClientCert != "" {
        isTLS = true
        rootCertPool := x509.NewCertPool()
        pem, err := ioutil.ReadFile("/path/mysqlCaCert")
        if err != nil {
            log.Fatal(err)
        }
        if ok := rootCertPool.AppendCertsFromPEM(pem); !ok {
            log.Fatal("Failed to append PEM.")
        }
        clientCert := make([]tls.Certificate, 0, 1)
        certs, err := tls.LoadX509KeyPair("/path/mysqlClientCert", "/path/mysqlClientKey")
        if err != nil {
            log.Fatal(err)
        }
        clientCert = append(clientCert, certs)
        mysql.RegisterTLSConfig("custom", &tls.Config{
            RootCAs:      rootCertPool,
            Certificates: clientCert,
        })
    }
    
    // try to connect to mysql database.
    cfg := mysql.Config{
        User:   username,
        Passwd: password,
        Addr:   server, //IP:PORT
        Net:    "tcp",
        DBName: database,
        Loc: time.Local,
        AllowNativePasswords: true,
        Params: o,
    }
    
    if isTLS == true {
        cfg.TLSConfig = "custom"
    }
    
    str := cfg.FormatDSN()
    
    db, err := gorm.Open("mysql", str)
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 metadata提取的PDF元数据,如何转换为一个Excel
  • ¥15 关于arduino编程toCharArray()函数的使用
  • ¥100 vc++混合CEF采用CLR方式编译报错
  • ¥15 coze 的插件输入飞书多维表格 app_token 后一直显示错误,如何解决?
  • ¥15 vite+vue3+plyr播放本地public文件夹下视频无法加载
  • ¥15 c#逐行读取txt文本,但是每一行里面数据之间空格数量不同
  • ¥50 如何openEuler 22.03上安装配置drbd
  • ¥20 ING91680C BLE5.3 芯片怎么实现串口收发数据
  • ¥15 无线连接树莓派,无法执行update,如何解决?(相关搜索:软件下载)
  • ¥15 Windows11, backspace, enter, space键失灵