@matthewb thanks for the detailed explanation , I just have one last confusion,
--tls-ca=TLS-CA Path to certificate authority certificate file
--tls-cert=TLS-CERT Path to client certificate file
--tls-key=TLS-KEY Path to client key file
these fields when adding mysql service are again the self-signed certs created by me right?
Thanks a lot, this helped me clear a lot of confusions I had.