# Getting error after configuration Percona Xtradb 8.0?

**URL:** <https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894>\
**Category:** Percona XtraDB Cluster 8.x\
**Created:** [August 12, 2020, 7:30am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894 "2020-08-12T07:30:30Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![lokesh123](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lokesh123/32/5519_2.png) [@lokesh123](https://forums.percona.com/u/lokesh123)\
**Post date:** [August 12, 2020, 7:30am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/1 "2020-08-12T07:30:30Z")

</div>

– Unit mysql.service has begun starting up.Aug 12 12:57:09 ip-10-60-1-11.ap-north-1.compute.internal systemd[1]: mysql.service: Main process exited, code=exited, status=1/FAILUREAug 12 12:57:09 ip-10-60-1-11.ap-north-1.compute.internal mysql-systemd[23680]:&nbsp; WARNING: mysql pid file /var/run/mysqld/mysqld.pid empty or not readableAug 12 12:57:09 ip-10-60-1-11.ap-north-1.compute.internal mysql-systemd[23680]:&nbsp; WARNING: mysql may be already deadAug 12 12:57:09 ip-10-60-1-11.ap-north-1.compute.internal systemd[1]: mysql.service: Failed with result ‘exit-code’.Aug 12 12:57:09 ip-10-60-1-11.ap-north-1.compute.internal systemd[1]: Failed to start Percona XtraDB Cluster.-- Subject: Unit mysql.service has failed-- Defined-By: systemd

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [August 12, 2020, 11:47am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/2 "2020-08-12T11:47:51Z")

</div>

Hi Lokesh123,  
There’s no helpful information here. You need to provide MySQL’s error log, typically located at /var/log/mysqld.log

---

<div class="post-metadata">

**Author:** ![lokesh123](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lokesh123/32/5519_2.png) [@lokesh123](https://forums.percona.com/u/lokesh123)\
**Post date:** [August 12, 2020, 12:58pm UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/3 "2020-08-12T12:58:42Z")

</div>

----2020-08-12T18:24:09.109559Z 0 [Note] [MY-000000] [Galera] PC protocol downgrade 1 -\> 02020-08-12T18:24:09.109604Z 0 [Note] [MY-000000] [Galera] Current view of cluster as seen by this nodeview ((empty))2020-08-12T18:24:09.109757Z 0 [ERROR] [MY-000000] [Galera] failed to open gcomm backend connection: 110: failed to reach primary view (pc.wait\_prim\_timeout): 110 (Connection timed out)&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;at gcomm/src/pc.cpp:connect():1592020-08-12T18:24:09.109788Z 0 [ERROR] [MY-000000] [Galera] gcs/src/gcs\_core.cpp:gcs\_core\_open():220: Failed to open backend connection: -110 (Connection timed out)2020-08-12T18:24:09.109891Z 0 [ERROR] [MY-000000] [Galera] gcs/src/gcs.cpp:gcs\_open():1700: Failed to open channel ‘pxc-cluster’ at ‘gcomm://10.60.1.157,10.60.1.129’: -110 (Connection timed out)2020-08-12T18:24:09.109913Z 0 [ERROR] [MY-000000] [Galera] gcs connect failed: Connection timed out2020-08-12T18:24:09.109934Z 0 [ERROR] [MY-000000] [WSREP] Provider/Node (gcomm://10.60.1.157,10.60.1.129) failed to establish connection with cluster (reason: 7)2020-08-12T18:24:09.109955Z 0 [ERROR] [MY-010119] [Server] Aborting2020-08-12T18:24:09.110233Z 0 [System] [MY-010910] [Server] /usr/sbin/mysqld: Shutdown complete (mysqld 8.0.19-10)&nbsp; Percona XtraDB Cluster (GPL), Release rel10, Revision 727f180, WSREP version 26.4.3.2020-08-12T18:24:09.110519Z 0 [Note] [MY-000000] [Galera] dtor state: CLOSED2020-08-12T18:24:09.110561Z 0 [Note] [MY-000000] [Galera] MemPool(TrxHandleSlave): hit ratio: 0, misses: 0, in use: 0, in pool: 02020-08-12T18:24:09.112795Z 0 [Note] [MY-000000] [Galera] apply mon: entered 02020-08-12T18:24:09.115115Z 0 [Note] [MY-000000] [Galera] apply mon: entered 02020-08-12T18:24:09.117348Z 0 [Note] [MY-000000] [Galera] apply mon: entered 02020-08-12T18:24:09.117499Z 0 [Note] [MY-000000] [Galera] cert index usage at exit 02020-08-12T18:24:09.117515Z 0 [Note] [MY-000000] [Galera] cert trx map usage at exit 02020-08-12T18:24:09.117525Z 0 [Note] [MY-000000] [Galera] deps set usage at exit 02020-08-12T18:24:09.117541Z 0 [Note] [MY-000000] [Galera] avg deps dist 02020-08-12T18:24:09.117550Z 0 [Note] [MY-000000] [Galera] avg cert interval 02020-08-12T18:24:09.117557Z 0 [Note] [MY-000000] [Galera] cert index size 02020-08-12T18:24:09.117592Z 0 [Note] [MY-000000] [Galera] Service thread queue flushed.2020-08-12T18:24:09.117629Z 0 [Note] [MY-000000] [Galera] wsdb trx map usage 0 conn query map usage 02020-08-12T18:24:09.117644Z 0 [Note] [MY-000000] [Galera] MemPool(LocalTrxHandle): hit ratio: 0, misses: 0, in use: 0, in pool: 02020-08-12T18:24:09.118354Z 0 [Note] [MY-000000] [Galera] Flushing memory map to disk…

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [August 12, 2020, 3:49pm UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/4 "2020-08-12T15:49:27Z")

</div>

I see “Connection timed out” in many locations in your log file. This tells me that this node is unable to make contact with any other nodes in your cluster. Check firewalls or other networking access. Be sure to allow port 3306, 4444, and 4567

---

<div class="post-metadata">

**Author:** ![lokesh123](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lokesh123/32/5519_2.png) [@lokesh123](https://forums.percona.com/u/lokesh123)\
**Post date:** [August 12, 2020, 11:52pm UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/5 "2020-08-12T23:52:20Z")

</div>

firewalls are&nbsp; not installed in my system.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [August 13, 2020, 7:36am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/6 "2020-08-13T07:36:16Z")

</div>

Are you in AWS? or is this all local on the same machine. Are you trying to start node #1? If so, you must always bootstrap the first node of the cluster.

---

<div class="post-metadata">

**Author:** ![lokesh123](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lokesh123/32/5519_2.png) [@lokesh123](https://forums.percona.com/u/lokesh123)\
**Post date:** [August 14, 2020, 2:18am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/7 "2020-08-14T02:18:38Z")

</div>

Matthewb On AWS:  
  
I got there was some issue with ssl configuration.  
when I set&nbsp;  
pxc-encrypt-cluster-traffic=OFF cluster is working fine.  
But I run with “pxc-encrypt-cluster-traffic=ON” default with below configuration and bootstap node1 is working but when I start with same configuration&nbsp; my second node not able to start&nbsp; with some errors.&nbsp;  
  
# Template my.cnf for PXC  
# Edit to your requirements.**[client]****socket=/var/lib/mysql/mysql.sock ****ssl-ca=/home/adminuser/srt/ca.pem**** ssl-key=/home/adminuser/srt/client-key.pem ****ssl-cert=/home/adminuser/srt/client-cert.pem**  
**[mysqld]****server-id=1 ****datadir=/var/lib/mysql**** socket=/var/lib/mysql/mysql.sock ****log-error=/var/log/mysqld.log**** pid-file=/var/run/mysqld/mysqld.pid ****# Binary log expiration period is 604800 seconds, which equals 7 days**  
**binlog\_expire\_logs\_seconds=604800**** ######## wsrep ###############**  
**# Path to Galera library**** wsrep\_provider=/usr/lib64/galera4/libgalera\_smm.so ****# Cluster connection URL contains IPs of nodes**  
**#If no IP is found, this implies that a new cluster needs to be created,**** #in order to do that you need to bootstrap this node ****wsrep\_cluster\_address=gcomm://192.168.1.129,192.168.1.157,192.168.1.164**** # In order for Galera to work correctly binlog format should be ROW**  
**binlog\_format=ROW**** # Slave thread to use**  
**wsrep\_slave\_threads=8**** wsrep\_log\_conflicts**  
**# This changes how InnoDB autoincrement locks are managed and is a requirement for Galera**  
**innodb\_autoinc\_lock\_mode=2**** # Node IP address**  
**wsrep\_node\_address=192.168.1.157**** # Cluster name ****wsrep\_cluster\_name=pxc-cluster**** #If wsrep\_node\_name is not specified,&nbsp; then system hostname will be used**  
**wsrep\_node\_name=pxc-cluster-node-2**** #pxc\_strict\_mode allowed values: DISABLED,PERMISSIVE,ENFORCING,MASTER**  
**pxc\_strict\_mode=ENFORCING**** wsrep\_sst\_method=xtrabackup-v2**  
**wsrep\_provider\_options=”socket.ssl\_key=/home/adminuser/srt/server-key.pem;socket.ssl\_cert=/home/adminuser/srt/server-cert.pem;socket.ssl\_ca=/home/adminuser/srt/ca.pem”**  
**[sst]**  
**encrypt=4**** ssl-key=/home/adminuser/srt/server-key.pem ****ssl-ca=/home/adminuser/srt/ca.pem**** ssl-cert=/home/adminuser/srt/server-cert.pem**  
  
** ~~logs:~~ **  
iod = PT1S; evs.max\_install\_timeouts = 3; evs.send\_window = 10; evs.stats\_report\_period = PT1M; evs.suspect\_timeout = PT5S; evs.user\_send\_window = 4; evs.view\_forget\_timeout = PT24H; gcache.dir = /var/lib/mysql/; gcache.freeze\_purge\_at\_seqno = -1; gcache.keep\_pages\_count = 0; gcache.keep\_pages\_size = 0; gcache.mem\_size = 0; gcache.name = galera.cache; gcache.page\_size = 128M; gcache.recover = yes; gcache.size = 128M; gcomm.thread\_prio = ; gcs.fc\_debug = 0; gcs.fc\_factor = 1.0; gcs.fc\_limit = 100; gcs.fc\_master\_slave = no; gcs.max\_packet\_size = 64500; gcs.max\_throttle = 0.25; gcs.recv\_q\_hard\_limit = 9223372036854775807; gcs.recv\_q\_soft\_limit = 0.25; gcs.sync\_donor = no; gmcast.segment = 0; gmcast.version = 0; pc.announce\_timeout = PT3S; pc.checksum = false; pc.ignore\_quorum = false; pc.ignore\_sb = false; pc.npvo = false; pc.recovery = true; pc.version = 0; pc.wait\_prim = true; pc.wait\_prim\_timeout = PT30S; pc.weight = 1; protonet.backend = asio; protonet.version = 0; repl.causal\_read\_timeout = PT30S; repl.commit\_order = 3; repl.key\_format = FLAT8; repl.max\_ws\_size = 2147483647; repl.proto\_max = 10; socket.checksum = 2; socket.recv\_buf\_size = 212992;2020-08-14T07:10:45.279603Z 0 [Note] [MY-000000] [Galera] Service thread queue flushed.2020-08-14T07:10:45.279693Z 0 [Note] [MY-000000] [Galera] ####### Assign initial position for certification: 488e520d-dd4e-11ea-8402-5725b4971a3d:66, protocol version: -12020-08-14T07:10:45.279759Z 0 [Note] [MY-000000] [WSREP] Starting replication2020-08-14T07:10:45.279820Z 0 [Note] [MY-000000] [Galera] Connecting with bootstrap option: 02020-08-14T07:10:45.279876Z 0 [Note] [MY-000000] [Galera] Setting GCS initial position to 488e520d-dd4e-11ea-8402-5725b4971a3d:662020-08-14T07:10:45.279969Z 0 [Note] [MY-000000] [Galera] protonet asio version 02020-08-14T07:10:45.280276Z 0 [Note] [MY-000000] [Galera] Using CRC-32C for message checksums.2020-08-14T07:10:45.280358Z 0 [Note] [MY-000000] [Galera] backend: asio2020-08-14T07:10:45.280466Z 0 [Note] [MY-000000] [Galera] gcomm thread scheduling priority set to other:02020-08-14T07:10:45.280586Z 0 [Warning] [MY-000000] [Galera] Fail to access the file (/var/lib/mysql//gvwstate.dat) error (No such file or directory). It is possible if node is booting for first time or re-booting after a graceful shutdown2020-08-14T07:10:45.280651Z 0 [Note] [MY-000000] [Galera] Restoring primary-component from disk failed. Either node is booting for first time or re-booting after a graceful shutdown2020-08-14T07:10:45.280865Z 0 [Note] [MY-000000] [Galera] GMCast version 02020-08-14T07:10:45.281052Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) listening at tcp://0.0.0.0:45672020-08-14T07:10:45.281122Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) multicast: , ttl: 12020-08-14T07:10:45.281421Z 0 [Note] [MY-000000] [Galera] EVS version 12020-08-14T07:10:45.281546Z 0 [Note] [MY-000000] [Galera] gcomm: connecting to group ‘pxc-cluster’, peer '192.168.1.129:,192.168.1.157:,192.168.1.164:'2020-08-14T07:10:45.282224Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) Found matching local endpoint for a connection, blacklisting address tcp://192.168.1.129:45672020-08-14T07:10:48.282764Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) connection to peer 00000000 with addr tcp://192.168.1.157:4567 timed out, no messages seen in PT3S (gmcast.peer\_timeout)2020-08-14T07:10:48.283343Z 0 [Note] [MY-000000] [Galera] announce period timed out (pc.announce\_timeout)2020-08-14T07:10:48.283494Z 0 [Note] [MY-000000] [Galera] EVS version upgrade 0 -\> 12020-08-14T07:10:48.283584Z 0 [Note] [MY-000000] [Galera] PC protocol upgrade 0 -\> 12020-08-14T07:10:48.283679Z 0 [Warning] [MY-000000] [Galera] no nodes coming from prim view, prim not possible2020-08-14T07:10:48.283772Z 0 [Note] [MY-000000] [Galera] Current view of cluster as seen by this nodeview (view\_id(NON\_PRIM,45a01e3c,1)memb {&nbsp; &nbsp; &nbsp; &nbsp; 45a01e3c,0&nbsp; &nbsp; &nbsp; &nbsp; }joined {&nbsp; &nbsp; &nbsp; &nbsp; }left {&nbsp; &nbsp; &nbsp; &nbsp; }partitioned {&nbsp; &nbsp; &nbsp; &nbsp; })&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  
left {&nbsp; &nbsp; &nbsp; &nbsp; }partitioned {&nbsp; &nbsp; &nbsp; &nbsp; })2020-08-14T07:10:48.783973Z 0 [Warning] [MY-000000] [Galera] last inactive check more than PT1.5S (3\*evs.inactive\_check\_period) ago (PT3.50253S), skipping check2020-08-14T07:10:52.783995Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) connection to peer 00000000 with addr tcp://192.168.1.157:4567 timed out, no messages seen in PT3S (gmcast.peer\_timeout)2020-08-14T07:10:57.284705Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) connection to peer 00000000 with addr tcp://192.168.1.157:4567 timed out, no messages seen in PT3S (gmcast.peer\_timeout)2020-08-14T07:11:01.785258Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) connection to peer 00000000 with addr tcp://192.168.1.157:4567 timed out, no messages seen in PT3S (gmcast.peer\_timeout)2020-08-14T07:11:06.285896Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) connection to peer 00000000 with addr tcp://192.168.1.157:4567 timed out, no messages seen in PT3S (gmcast.peer\_timeout)2020-08-14T07:11:10.286798Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) connection to peer 00000000 with addr tcp://192.168.1.157:4567 timed out, no messages seen in PT3S (gmcast.peer\_timeout)2020-08-14T07:11:14.287545Z 0 [Note] [MY-000000] [Galera] (45a01e3c, ‘tcp://0.0.0.0:4567’) connection to peer 00000000 with addr tcp://192.168.1.157:4567 timed out, no messages seen in PT3S (gmcast.peer\_timeout)2020-08-14T07:11:18.292483Z 0 [Note] [MY-000000] [Galera] PC protocol downgrade 1 -\> 02020-08-14T07:11:18.292681Z 0 [Note] [MY-000000] [Galera] Current view of cluster as seen by this nodeview ((empty))2020-08-14T07:11:18.293109Z 0 [ERROR] [MY-000000] [Galera] failed to open gcomm backend connection: 110: failed to reach primary view (pc.wait\_prim\_timeout): 110 (Connection timed out)&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;at gcomm/src/pc.cpp:connect():1592020-08-14T07:11:18.293157Z 0 [ERROR] [MY-000000] [Galera] gcs/src/gcs\_core.cpp:gcs\_core\_open():220: Failed to open backend connection: -110 (Connection timed out)2020-08-14T07:11:18.293216Z 0 [ERROR] [MY-000000] [Galera] gcs/src/gcs.cpp:gcs\_open():1700: Failed to open channel ‘pxc-cluster’ at ‘gcomm://192.168.1.129,192.168.1.157,192.168.1.164’: -110 (Connection timed out)2020-08-14T07:11:18.293228Z 0 [ERROR] [MY-000000] [Galera] gcs connect failed: Connection timed out2020-08-14T07:11:18.293239Z 0 [ERROR] [MY-000000] [WSREP] Provider/Node (gcomm://192.168.1.129,192.168.1.157,192.168.1.164) failed to establish connection with cluster (reason: 7)2020-08-14T07:11:18.293251Z 0 [ERROR] [MY-010119] [Server] Aborting2020-08-14T07:11:18.293396Z 0 [System] [MY-010910] [Server] /usr/sbin/mysqld: Shutdown complete (mysqld 8.0.19-10)&nbsp; Percona XtraDB Cluster (GPL), Release rel10, Revision 727f180, WSREP version 26.4.3.2020-08-14T07:11:18.293611Z 0 [Note] [MY-000000] [Galera] dtor state: CLOSED2020-08-14T07:11:18.293633Z 0 [Note] [MY-000000] [Galera] MemPool(TrxHandleSlave): hit ratio: 0, misses: 0, in use: 0, in pool: 02020-08-14T07:11:18.295832Z 0 [Note] [MY-000000] [Galera] apply mon: entered 02020-08-14T07:11:18.297998Z 0 [Note] [MY-000000] [Galera] apply mon: entered 02020-08-14T07:11:18.300149Z 0 [Note] [MY-000000] [Galera] apply mon: entered 02020-08-14T07:11:18.300168Z 0 [Note] [MY-000000] [Galera] cert index usage at exit 02020-08-14T07:11:18.300173Z 0 [Note] [MY-000000] [Galera] cert trx map usage at exit 02020-08-14T07:11:18.300177Z 0 [Note] [MY-000000] [Galera] deps set usage at exit 02020-08-14T07:11:18.300184Z 0 [Note] [MY-000000] [Galera] avg deps dist 02020-08-14T07:11:18.300188Z 0 [Note] [MY-000000] [Galera] avg cert interval 02020-08-14T07:11:18.300193Z 0 [Note] [MY-000000] [Galera] cert index size 02020-08-14T07:11:18.300210Z 0 [Note] [MY-000000] [Galera] Service thread queue flushed.2020-08-14T07:11:18.300223Z 0 [Note] [MY-000000] [Galera] wsdb trx map usage 0 conn query map usage 02020-08-14T07:11:18.300229Z 0 [Note] [MY-000000] [Galera] MemPool(LocalTrxHandle): hit ratio: 0, misses: 0, in use: 0, in pool: 02020-08-14T07:11:18.300773Z 0 [Note] [MY-000000] [Galera] Flushing memory map to disk…&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [August 14, 2020, 8:01am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/8 "2020-08-14T08:01:58Z")

</div>

In order to use SSL and pxc-encrypt-cluster-traffic=ON, you must&nbsp; **MANUALLY** copy the SSL certificates that are created on node #1 after you bootstrap it to all other nodes. SSL certificates are&nbsp; **NOT** transfered automatically to any joining nodes.  
So, shut down your cluster cleanly. Then, set pxc-encrypt-cluster-traffic=ON on node #1 and bootstrap it. This should come up with no issues. Next, copy the SSL certs from node #1 to node #2. Set node#2 pxc-encrypt-cluster-traffic=ON and start it normally. It should connect to node #1. Repeat for #3.

---

<div class="post-metadata">

**Author:** ![lokesh123](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lokesh123/32/5519_2.png) [@lokesh123](https://forums.percona.com/u/lokesh123)\
**Post date:** [August 15, 2020, 8:32am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/9 "2020-08-15T08:32:29Z")

</div>

@mathhwes IS this right configuration for SSL ?  
  
And&nbsp;  
  
&nbsp;Is there a particular&nbsp; location to put all SSL certification or I can put any where as like in&nbsp; below&nbsp; configuration?  
  
**[mysqld]**  
**&nbsp;pxc-encrypt-cluster-traffic=ON**  
**wsrep\_provider\_options=”socket.ssl\_key=/home/adminuser/srt/server-key.pem;socket.ssl\_cert=/home/adminuser/srt/server-cert.pem;socket.ssl\_ca=/home/adminuser/srt/ca.pem”**  
**[sst]**  
**encrypt=4**** ssl-key=/home/adminuser/srt/server-key.pem ****ssl-ca=/home/adminuser/srt/ca.pem**** ssl-cert=/home/adminuser/srt/server-cert.pem**

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [August 15, 2020, 8:50am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/10 "2020-08-15T08:50:57Z")

</div>

Yes, that should be good. Now, bootstrap that node #1, and copy \*.pem to same location on all nodes and configure the same.

---

<div class="post-metadata">

**Author:** ![lokesh123](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lokesh123/32/5519_2.png) [@lokesh123](https://forums.percona.com/u/lokesh123)\
**Post date:** [August 15, 2020, 10:09am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/11 "2020-08-15T10:09:18Z")

</div>

wsrep\_provider\_options=”socket.ssl\_key=/home/adminuser/server-key.pem;socket.ssl\_cert=/home/adminuser/server-cert.pem;socket.ssl\_ca=/home/adminuser/ca.pem”  
pxc-encrypt-cluster-traffic=ON[sst]encrypt=4ssl-key=/home/adminuser/server-key.pemssl-ca=/home/adminuser/ca.pemssl-cert=/home/adminuser/server-cert.pem  
getting same logs not resolved

---

<div class="post-metadata">

**Author:** ![lokesh123](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lokesh123/32/5519_2.png) [@lokesh123](https://forums.percona.com/u/lokesh123)\
**Post date:** [August 15, 2020, 10:32am UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/12 "2020-08-15T10:32:39Z")

</div>

Also when I am trying with first node1&nbsp; putting&nbsp; in config  
  
ssl-key=/home/adminuser/srt/server-key.pemssl-ca=/home/adminuser/srt/ca.pemssl-cert=/home/adminuser/srt/server-cert.pem  
  
It has to show the location for SSL&nbsp; files is&nbsp;&nbsp;  
  
**/home/adminuser/srt/ca.pem**  
**/home/adminuser/srt/server-cert.pem**  
**/home/adminuser/srt/server-key.pem**  
  
**But It shows last one**  
  
&nbsp;show variables like ‘%ssl%’&nbsp; &nbsp; -\> ;±-------------------±----------------+| Variable\_name&nbsp; &nbsp; &nbsp; | Value&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|±-------------------±----------------+| have\_openssl&nbsp; &nbsp; &nbsp; &nbsp;| YES&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| have\_ssl&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;| YES&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| mysqlx\_ssl\_ca&nbsp; &nbsp; &nbsp; |&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| mysqlx\_ssl\_capath&nbsp; |&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| mysqlx\_ssl\_cert&nbsp; &nbsp; |&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| mysqlx\_ssl\_cipher&nbsp; |&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| mysqlx\_ssl\_crl&nbsp; &nbsp; &nbsp;|&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| mysqlx\_ssl\_crlpath |&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| mysqlx\_ssl\_key&nbsp; &nbsp; &nbsp;|&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;| **| ssl\_ca&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;| ca.pem&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; |** | ssl\_capath&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;| **| ssl\_cert&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;| server-cert.pem |** | ssl\_cipher&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| ssl\_crl&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; |&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| ssl\_crlpath&nbsp; &nbsp; &nbsp; &nbsp; |&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|| ssl\_fips\_mode&nbsp; &nbsp; &nbsp; | OFF&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;| **| ssl\_key&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | server-key.pem&nbsp; |** ±-------------------±----------------+17 rows in set (0.01 sec)

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [August 15, 2020, 12:35pm UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/13 "2020-08-15T12:35:27Z")

</div>

Stop node #1. Put these lines:

```auto
pxc-encrypt-cluster-traffic=ON
ssl-key=/home/adminuser/server-key.pem
ssl-ca=/home/adminuser/ca.pem
ssl-cert=/home/adminuser/server-cert.pem

```

inside [mysqld]  
Remove the ENTIRE [sst] section.  
Remove “wsrep\_provider\_options”.  
Bootstrap node 1. Put the SAME CONFIG as above into the other nodes. Start them normally.

---

<div class="post-metadata">

**Author:** ![lokesh123](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lokesh123/32/5519_2.png) [@lokesh123](https://forums.percona.com/u/lokesh123)\
**Post date:** [August 15, 2020, 3:27pm UTC](https://forums.percona.com/t/getting-error-after-configuration-percona-xtradb-8-0/7894/14 "2020-08-15T15:27:55Z")

</div>

Thank-you so much Matthewb&nbsp; for your valuable&nbsp; time and help. =D  
It’s working.
