# Proxysql uses default cipher on updating ssl\_p2s\_cipher to ECDHE-ECDSA-AES256-GCM-SHA384

**URL:** <https://forums.percona.com/t/proxysql-uses-default-cipher-on-updating-ssl-p2s-cipher-to-ecdhe-ecdsa-aes256-gcm-sha384/17301>\
**Category:** Polyglot Projects\
**Created:** [September 5, 2022, 5:57am UTC](https://forums.percona.com/t/proxysql-uses-default-cipher-on-updating-ssl-p2s-cipher-to-ecdhe-ecdsa-aes256-gcm-sha384/17301 "2022-09-05T05:57:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![preethi\_subbu](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/preethi_subbu/32/3204_2.png) [@preethi\_subbu](https://forums.percona.com/u/preethi_subbu)\
**Post date:** [September 5, 2022, 5:57am UTC](https://forums.percona.com/t/proxysql-uses-default-cipher-on-updating-ssl-p2s-cipher-to-ecdhe-ecdsa-aes256-gcm-sha384/17301/1 "2022-09-05T05:57:33Z")

</div>

I need to enable SSL only for front-end connections. Sharing the configuration for better clarity.

±---------------------±------------------------------+  
| variable\_name | variable\_value |  
±---------------------±------------------------------+  
| mysql-ssl\_p2s\_cipher | ECDHE-ECDSA-AES256-GCM-SHA384 |  
±---------------------±------------------------------+  
1 row in set (0.00 sec)

mysql/bin/mysql -uadmin -p -P6032 -h127.0.0.1 -e ‘\s’ | grep -P ‘SSL|Connection’  
Connection id: 1441  
SSL: Cipher in use is DHE-RSA-AES256-SHA  
Connection: 127.0.0.1 via TCP/IP```

From this I could see only default cipher is used in front-end connections.

On explicitly mentioning --ssl --ssl-cipher=ECDHE-ECDSA-AES256-GCM-SHA384  
Getting SSL connection error: Failed to set ciphers to use.

Able to connect only with default cipher.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [September 5, 2022, 4:07pm UTC](https://forums.percona.com/t/proxysql-uses-default-cipher-on-updating-ssl-p2s-cipher-to-ecdhe-ecdsa-aes256-gcm-sha384/17301/2 "2022-09-05T16:07:13Z")

</div>

I verified this. You should open a bug report with ProxySQL github.

```auto
$ mysql -h app -usbuser -psbPass1234# -BN -e '\s' --ssl-cipher="ECDHE-ECDSA-AES256-GCM-SHA384" | grep -P 'SSL|Connection|Server'
mysql: [Warning] Using a password on the command line interface can be insecure.
mysql Ver 8.0.28-20 for Linux on x86_64 (Percona Server (GPL), Release 20, Revision fd4b5a776a6)
Connection id: 415
SSL: Cipher in use is TLS_AES_256_GCM_SHA384
Server version: 5.5.30 (ProxySQL)
Connection: app via TCP/IP
Server characterset:	utf8mb4

# mysql -uadmin -padmin -h 127.0.0.1 -P 6032 -e "show variables like '%ssl%'"
mysql: [Warning] Using a password on the command line interface can be insecure.
+-------------------------------------+--------------------------------+
| Variable_name | Value |
+-------------------------------------+--------------------------------+
| mysql-have_ssl | true |
| mysql-session_idle_show_processlist | true |
| mysql-show_processlist_extended | 0 |
| mysql-ssl_p2s_ca | /etc/ssl/mysql/ca.pem |
| mysql-ssl_p2s_capath | |
| mysql-ssl_p2s_cert | /etc/ssl/mysql/client-cert.pem |
| mysql-ssl_p2s_key | /etc/ssl/mysql/client-key.pem |
| mysql-ssl_p2s_cipher | ECDHE-RSA-AES256-SHA |
| mysql-ssl_p2s_crl | |
| mysql-ssl_p2s_crlpath | |
+-------------------------------------+--------------------------------+

```
