Re: [Shorewall-users] Security question around MySQL Replication

2017-09-12 Thread Davide Marchi
---Bill Shirley- Il 2017-09-11 19:01 Bill Shirley ha scritto: Both are good suggestions: block all IP addresses at the firewall except your slave, configure MySQL SSL.  See: https://www.mail-archive.com/shorewall-users@lists.sourceforge.net/msg20502.html Of course,

Re: [Shorewall-users] Security question around MySQL Replication

2017-09-11 Thread Bill Shirley
Both are good suggestions: block all IP addresses at the firewall except your slave, configure MySQL SSL.  See: https://www.mail-archive.com/shorewall-users@lists.sourceforge.net/msg20502.html Of course, you'll have to create the certificates and tweak the values in the CHANGE MASTER. Bill On

Re: [Shorewall-users] Security question around MySQL Replication

2017-09-11 Thread Dominic Benson
On 11/09/17 13:49, Phil Stracchino wrote: > On 09/11/17 07:29, Davide Marchi wrote: >> Hi friends, >> >> I've enabled between two servers (VPS Debian Jessie), the MySQL >> Replication feature. >> For this I've open the "3306" port. >> >> >> My question: is this a safe operation or should I also

Re: [Shorewall-users] Security question around MySQL Replication

2017-09-11 Thread Phil Stracchino
On 09/11/17 07:29, Davide Marchi wrote: > Hi friends, > > I've enabled between two servers (VPS Debian Jessie), the MySQL > Replication feature. > For this I've open the "3306" port. > > > My question: is this a safe operation or should I also do something > other for improve the firewall

[Shorewall-users] Security question around MySQL Replication

2017-09-11 Thread Davide Marchi
Hi friends, I've enabled between two servers (VPS Debian Jessie), the MySQL Replication feature. For this I've open the "3306" port. My question: is this a safe operation or should I also do something other for improve the firewall level, always without the risk or compromising