When using Mysql, you may encounter the following situations: 1. The information is important and you want to encrypt the communication. 2. Some ports, such as port 3306, are disabled by the router. To first
When using Mysql, you may encounter the following situations: 1. The information is important and you want to encrypt the communication. 2. Some ports, such as port 3306, are disabled by the router. To first
In many cases, you may encounter the following situations when using Mysql:
1. Information is important, and communication is expected to be encrypted.
2. Some ports, such as port 3306, are disabled by the router.
A Direct Solution to the first problem is to change the mysql code or use some certificates. However, this method is obviously not very simple.
Another method is to connect to a remote Mysql through the SSH channel, which is quite simple.
1. Create an SSH Channel
Just type the following command locally:
Ssh-fNg-L 3307: 127.0.0.1: 3306 myuser@remotehost.com
The command tells ssh to log in to remotehost.com as myuser, go into the background (-f) and not execute any remote command (-N ), and set up port-forwarding (-L localport: localhost: remoteport ). in this case, we forward port 3307 on localhost to port 3306 on remotehost.com.
2. Connect to Mysql
Now, you can connect to a remote database locally, just like accessing a local database.
Mysql-h 127.0.0.1-P 3307-u dbuser-p db
The command tells the local MySQL client to connect to localhost port 3307 (which is forwarded via ssh to remotehost.com: 3306 ). the exchange of data between client and server is now sent over the encrypted ssh connection.
You can also use Mysql Query Brower to access port 3307 of the Client.
Similarly, use PHP to access:
$ Smysql = mysql_connect ("127.0.0.1: 3307", "dbuser", "PASS ");
Mysql_select_db ("db", $ smysql );
?>
Making It A Daemon
A quick and dirty way to make sure the connection runs on startup and respawns on failure is to add it to/etc/inittab and have the init process (the, uh, kernel) keep it going.
Add the following to/etc/inittab on each client:
Sm: 345: respawn:/usr/bin/ssh-Ng-L 3307: 127.0.0.1: 3306 myuser@remotehost.com
And that shoshould be all you need to do. send init the HUP signal (kill-HUP 1) to make it reload the configuration. to turn it off, comment out the line and HUP init again.