# ProxySQL Backend SSL Connection Error

**URL:** <https://forums.percona.com/t/proxysql-backend-ssl-connection-error/16519>\
**Category:** ProxySQL\
**Created:** [July 11, 2022, 5:45pm UTC](https://forums.percona.com/t/proxysql-backend-ssl-connection-error/16519 "2022-07-11T17:45:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![LukeYangJMA](https://avatars.discourse-cdn.com/v4/letter/l/0ea827/32.png) [@LukeYangJMA](https://forums.percona.com/u/LukeYangJMA)\
**Post date:** [July 11, 2022, 5:45pm UTC](https://forums.percona.com/t/proxysql-backend-ssl-connection-error/16519/1 "2022-07-11T17:45:41Z")

</div>

We have configured ProxySQL with Orchestrator to allow a front-end client to connect to two Percona servers running master slave replication. When disabling backend SSL, there are no connection issues between ProxySQL and Percona:

```auto
+-------------------------+------+------------------+-------------------------+---------------+
| hostname | port | time_start_us | connect_success_time_us | connect_error |
+-------------------------+------+------------------+-------------------------+---------------+
| master_percona_server | 3306 | 1657560485825536 | 8610 | NULL |
| slave_percona_server | 3306 | 1657560484730191 | 36817 | NULL |
+-------------------------+------+------------------+-------------------------+---------------+

```

However, when enabling SSL on all servers and specifying both mysql-ssl\_p2s\_cert and mysql-ssl\_p2s\_key in ProxySQL, the following errors occur:

```auto
+-------------------------+------+------------------+-------------------------+----------------------------------------------+
| hostname | port | time_start_us | connect_success_time_us | connect_error |
+-------------------------+------+------------------+-------------------------+----------------------------------------------+
| master_percona_server | 3306 | 1657560922780474 | 0 | Lost connection to MySQL server during query |
| slave_percona_server | 3306 | 1657560921681621 | 0 | Lost connection to MySQL server during query |
+-------------------------+------+------------------+-------------------------+----------------------------------------------+

```

These are things we have already considered:

- Copied LetsEncrypt Certbot fullchain.pem and privkey.pem into /var/lib/proxysql
- chmod 600 fullchain.pem and privkey.pem
- chown proxysql:proxysql fullchain.pem and privkey.pem
- No errors when starting ProxySQL ([INFO] SSL keys/certificates found in datadir (/var/lib/proxysql): loading them)

**Questions:**

1. Does anyone have any thoughts on why might coming across this connection error?
2. We also have SSL enabled on the front-end client. When connecting to Percona through ProxySQL without specifying the path of mysql-ssl\_p2s\_cert and mysql-ssl\_p2s\_key in ProxySQL:

```auto
$ mysql -h127.0.0.1 -P6033 -utest_user -ptest_password -e 'SHOW SESSION STATUS LIKE "Ssl_cipher"'

```

The output is:

```auto
+---------------+------------------------+
| Variable_name | Value |
+---------------+------------------------+
| Ssl_cipher | TLS_AES_256_GCM_SHA384 |
+---------------+------------------------+

```

This should indicate that the connection session is encrypted. Therefore, is it even necessary to configure backend SSL on ProxySQL?

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [July 12, 2022, 12:35am UTC](https://forums.percona.com/t/proxysql-backend-ssl-connection-error/16519/2 "2022-07-12T00:35:26Z")

</div>

Do you have `use_ssl` set to 1 in `mysql_servers`?  
Did you set any of the mysql\_admin parameters to the SSL filenames?

---

<div class="post-metadata">

**Author:** ![LukeYangJMA](https://avatars.discourse-cdn.com/v4/letter/l/0ea827/32.png) [@LukeYangJMA](https://forums.percona.com/u/LukeYangJMA)\
**Post date:** [July 12, 2022, 2:44pm UTC](https://forums.percona.com/t/proxysql-backend-ssl-connection-error/16519/3 "2022-07-12T14:44:17Z")

</div>

Thanks for your response @matthewb,

We’ve set use\_ssl to 1 on mysql\_servers, ensuring that the servers were loaded to runtime and saved to disk. This was also confirmed when using the command:

```auto
SELECT * FROM mysql_servers;

```

In my.cnf on both the MySQL server that is running on the same server as ProxySQL and the Master-Slave Percona servers, we have added in the lines:

```auto
[mysqld]
admin-ssl=ON
admin_ssl_cert=/var/lib/mysql/fullchain.pem
admin_ssl_key=/var/lib/mysql/privkey.pem

```

The connection error still persists.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [July 12, 2022, 2:54pm UTC](https://forums.percona.com/t/proxysql-backend-ssl-connection-error/16519/4 "2022-07-12T14:54:57Z")

</div>

`admin-ssl*` parameters are only valid for the admin connection port. 🙂 Hence their name. You need to use the standard ssl\* parameters in your my.cnf to affect the standard connections.

---

<div class="post-metadata">

**Author:** ![LukeYangJMA](https://avatars.discourse-cdn.com/v4/letter/l/0ea827/32.png) [@LukeYangJMA](https://forums.percona.com/u/LukeYangJMA)\
**Post date:** [July 12, 2022, 4:03pm UTC](https://forums.percona.com/t/proxysql-backend-ssl-connection-error/16519/5 "2022-07-12T16:03:37Z")

</div>

Oh I see, thanks for letting me know about that @matthewb!

On another note, I realized that the connection error was through MySQL’s configuration of the ssl-ca. We’re using Let’s Encrypt and there was a whole set of things that needed to be done in order to get the ssl-ca to work. After fixing this the connection between ProxySQL and Percona with SSL enabled seems to work.

[Source](https://www.percona.com/blog/2020/12/04/how-to-configure-mysql-ssl-with-public-certificates/) (Even though the solution slightly stray from the direction this thread was originally going, I’ll leave it here in case anyone else finds themselves in a similar situation)

---

<div class="post-metadata">

**Author:** ![Michael\_Coburn](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/michael_coburn/32/18_2.png) [@Michael\_Coburn](https://forums.percona.com/u/Michael_Coburn)\
**Post date:** [July 12, 2022, 4:47pm UTC](https://forums.percona.com/t/proxysql-backend-ssl-connection-error/16519/6 "2022-07-12T16:47:34Z")

</div>


