SSL cert failed to verify: x509: certificate is not valid for any names, but wanted to match … | The server’s certificate has no Subject Alternative Names, such as a certificate MySQL generated on its own. | Install a certificate that names the server’s host. For a test server only, turn off Verify server certificate. |
SSL cert failed to verify: x509: certificate signed by unknown authority | Verification is on, and the CA from CA certificate source didn’t sign the server’s certificate. | Paste the CA that signed the server’s certificate, or point to it. |
SSL cert failed to verify: x509: certificate is valid for …, not … | Hostname isn’t one of the names in the server’s certificate. | Use a name from the certificate, or have the certificate reissued. |
Error 3159 (HY000): Connections using insecure transport are prohibited while --require_secure_transport=ON. | The server requires TLS, and TLS mode is Disabled. | Set TLS mode to TLS. |
Error 1045 (28000): Access denied for user '…'@'…' (using password: YES) | The password is wrong, or the account requires a client certificate and TLS mode isn’t Mutual TLS. | Check the password. For an account created with REQUIRE X509, set TLS mode to Mutual TLS. |
ssl_cert and ssl_key must be both set or unset | Only one of the client certificate and its private key is set. | Provide both. |
failed to read CA certificate file | File path points to a file the Bytebase server can’t read. | Check the path on the Bytebase server. |
Error 1229 (HY000): Variable '…' is a GLOBAL variable and should be set with SET GLOBAL | Extra Parameters holds a name the driver doesn’t recognize, which it sends to MySQL as a session variable. | Use the driver’s parameter instead, such as timeout rather than connect_timeout. |
connection parameter "allowAllFiles" is not allowed for security reasons | Extra Parameters includes allowAllFiles. | Remove it. |