# SSL enabled Proxysql - How to configure proxysql to allow only encrypted front-end connections?

**URL:** <https://forums.percona.com/t/ssl-enabled-proxysql-how-to-configure-proxysql-to-allow-only-encrypted-front-end-connections/26805>\
**Category:** Polyglot Projects\
**Created:** [November 27, 2023, 3:16pm UTC](https://forums.percona.com/t/ssl-enabled-proxysql-how-to-configure-proxysql-to-allow-only-encrypted-front-end-connections/26805 "2023-11-27T15:16:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![preethi\_subbu](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/preethi_subbu/32/3204_2.png) [@preethi\_subbu](https://forums.percona.com/u/preethi_subbu)\
**Post date:** [November 27, 2023, 3:16pm UTC](https://forums.percona.com/t/ssl-enabled-proxysql-how-to-configure-proxysql-to-allow-only-encrypted-front-end-connections/26805/1 "2023-11-27T15:16:58Z")

</div>

Hi,  
I have enabled SSL for front-end connections in proxysql-2.5.5.

```auto
select * from global_variables where variable_name LIKE 'mysql-have_ssl';
+----------------+----------------+
| variable_name | variable_value |
+----------------+----------------+
| mysql-have_ssl | 1 |
+----------------+----------------+

```

Connecting from java using mysql connector  
​String url = “jdbc:mysql://hostname:6033/db?useSSL=false”;​​

Sharing audit log details

```auto

```

How to configure ProxySQL to throw error when connections are not encrypted ?

---

<div class="post-metadata">

**Author:** ![Ivan\_Groenewold](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/ivan_groenewold/32/6299_2.png) [@Ivan\_Groenewold](https://forums.percona.com/u/Ivan_Groenewold)\
**Post date:** [November 27, 2023, 3:32pm UTC](https://forums.percona.com/t/ssl-enabled-proxysql-how-to-configure-proxysql-to-allow-only-encrypted-front-end-connections/26805/2 "2023-11-27T15:32:11Z")

</div>

Hi Preethi, you need to do that on a per-user basis. Update the mysql\_users table to feature use\_ssl=1 for all users.

---

<div class="post-metadata">

**Author:** ![preethi\_subbu](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/preethi_subbu/32/3204_2.png) [@preethi\_subbu](https://forums.percona.com/u/preethi_subbu)\
**Post date:** [November 30, 2023, 1:16pm UTC](https://forums.percona.com/t/ssl-enabled-proxysql-how-to-configure-proxysql-to-allow-only-encrypted-front-end-connections/26805/3 "2023-11-30T13:16:05Z")

</div>

Enabling use\_ssl in mysql\_users not for back-end connections ?  
Would like to know about making SSL mandatory for frontend connections.

---

<div class="post-metadata">

**Author:** ![Ivan\_Groenewold](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/ivan_groenewold/32/6299_2.png) [@Ivan\_Groenewold](https://forums.percona.com/u/Ivan_Groenewold)\
**Post date:** [November 30, 2023, 2:09pm UTC](https://forums.percona.com/t/ssl-enabled-proxysql-how-to-configure-proxysql-to-allow-only-encrypted-front-end-connections/26805/4 "2023-11-30T14:09:37Z")

</div>

mysql\_users is for frontend. For backend connections SSL is controlled by the mysql\_Servers table.
