Bug 88133 - RFE: place #skip-networking in /etc/my.cnf for mysql to avoid security issue
RFE: place #skip-networking in /etc/my.cnf for mysql to avoid security issue
Product: Red Hat Linux
Classification: Retired
Component: mysql (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Patrick Macdonald
David Lawrence
: FutureFeature
: 88134 (view as bug list)
Depends On:
  Show dependency treegraph
Reported: 2003-04-06 10:48 EDT by Bryce Nesbitt
Modified: 2007-04-18 12:52 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2003-11-10 13:23:34 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Bryce Nesbitt 2003-04-06 10:48:44 EDT
Description of problem:
Many people run mysql on the same machine as the web server, and thus don't need
external networking enabled at ALL.  A service that is turned off is always more
secure than a service that's turned on.

Mysql comes by default with:

Proposed solution (for /etc/my.cnf):
If you'd add a commented-out "skip networking" line in /etc/my.cnf, more people
would discover how to turn off networking:  



Comment 1 Patrick Macdonald 2003-04-07 09:02:10 EDT
*** Bug 88134 has been marked as a duplicate of this bug. ***
Comment 2 Patrick Macdonald 2003-04-07 09:31:46 EDT
Just marking this as an enhancement for now.  We'll take a look at it this week.
Comment 3 Patrick Macdonald 2003-11-10 13:23:34 EST
After thinking about this for a while, we will not be changing the 
my.cnf file with the additional requested information.  Not that 
there is never a need to skip networking, it's just that the default 
from MySQL is not to skip it.  There are several other options that a
user may wish to enable / disable depending on their situation.  We
would have to put all equally important switches into my.cnf (commented
out).  Users should look at the documentation for information on 
setting up their servers.    

Note You need to log in before you can comment on or make changes to this bug.