defcon 2015年08月04日 發佈html
推薦 0 推薦node
收藏 3 收藏,2.8k 瀏覽mysql
Step1: 檢測系統是否自帶安裝mysqllinux
#yum list installed | grep mysql
Step2: 刪除系統自帶的mysql及其依賴
命令:sql
# yum -y remove mysql-libs.x86_64
Step3: 給CentOS添加rpm源,而且選擇較新的源
命令:數據庫
#wget dev.mysql.com/get/mysql-community-release-el6-5.noarch.rpm#yum localinstall mysql-community-release-el6-5.noarch.rpm# yum repolist all | grep mysql# yum-config-manager --disable mysql55-community# yum-config-manager --disable mysql56-community# yum-config-manager --enable mysql57-community-dmr# yum repolist enabled | grep mysql
Step4:安裝mysql 服務器
命令:vim
# yum install mysql-community-server
Step5: 啓動mysql
命令:segmentfault
#service mysqld start
Step6: 查看mysql是否自啓動,而且設置開啓自啓動
命令:centos
# chkconfig --list | grep mysqld# chkconfig mysqld on
Step7: mysql安全設置
命令:安全
# mysql_secure_installation
參考相關文檔地址:
http://www.rackspace.com/knowledge_center/article/installing-mysql-server-on-centos
http://dev.mysql.com/doc/refman/5.7/en/linux-installation-yum-repo.html
http://www.cnblogs.com/xiaoluo501395377/archive/2013/04/07/3003278.html
一、備份原數據庫
[root@www ~] #mysqldump -u root –p -E –all-database > /home/db-backup.sql
加-E是由於mysqldump默認並不處理mysql的事件,須要本身指明是否導出事件。
copy一份my.cnf,待安裝mysql5.7的時候參照。
[root@www ~]# cp /etc/my.cnf /home/my.cnf
中止mysql服務
[root@www ~]# service mysqld stop
中止 mysqld: [肯定]
卸載舊mysql版本。
[root@www ~]# yum remove mysql mysql-server
已加載插件:fastestmirror, priorities, refresh-packagekit
設置移除進程
Loading mirror speeds from cached hostfile
* base: mirrors.skyshe.cn
* epel: mirrors.hustunique.com
* extras: mirrors.163.com
* rpmforge: mirrors.neusoft.edu.cn
* updates: mirrors.163.com
132 packages excluded due to repository priority protections
解決依賴關係
--> 執行事務檢查
---> Package mysql.i686 0:5.1.73-5.el6_6 will be 刪除
--> 處理依賴關係 mysql = 5.1.73-5.el6_6,它被軟件包 mysql-devel-5.1.73-5.el6_6.i 686 須要
---> Package mysql-server.i686 0:5.1.73-5.el6_6 will be 刪除
--> 執行事務檢查
---> Package mysql-devel.i686 0:5.1.73-5.el6_6 will be 刪除
--> 處理依賴關係 mysql-devel = 5.1.73-5.el6_6,它被軟件包 mysql-embedded-devel-5 .1.73-5.el6_6.i686 須要
--> 執行事務檢查
---> Package mysql-embedded-devel.i686 0:5.1.73-5.el6_6 will be 刪除
--> 完成依賴關係計算依賴關係解決
================================================================================
軟件包 架構 版本 倉庫 大小
================================================================================
正在刪除:
mysql i686 5.1.73-5.el6_6 @updates 2.3 M
mysql-server i686 5.1.73-5.el6_6 @updates 24 M
爲依賴而移除:
mysql-devel i686 5.1.73-5.el6_6 @updates 388 k
mysql-embedded-devel i686 5.1.73-5.el6_6 @updates 14 M事務概要
================================================================================
Remove 4 Package(s)Installed size: 41 M
肯定嗎?[y/N]:y
下載軟件包:
運行 rpm_check_debug
執行事務測試
事務測試成功
執行事務
正在刪除 : mysql-server-5.1.73-5.el6_6.i686 1/4
warning: /var/log/mysqld.log saved as /var/log/mysqld.log.rpmsave
正在刪除 : mysql-embedded-devel-5.1.73-5.el6_6.i686 2/4
正在刪除 : mysql-devel-5.1.73-5.el6_6.i686 3/4
正在刪除 : mysql-5.1.73-5.el6_6.i686 4/4
Verifying : mysql-5.1.73-5.el6_6.i686 1/4
Verifying : mysql-embedded-devel-5.1.73-5.el6_6.i686 2/4
Verifying : mysql-server-5.1.73-5.el6_6.i686 3/4
Verifying : mysql-devel-5.1.73-5.el6_6.i686 4/4刪除:
mysql.i686 0:5.1.73-5.el6_6 mysql-server.i686 0:5.1.73-5.el6_6做爲依賴被刪除:
mysql-devel.i686 0:5.1.73-5.el6_6 mysql-embedded-devel.i686 0:5.1.73-5.el6_6完畢!
[root@www download]# yum remove mysql-embedded mysql-libs
… #刪除中…
若是centos安裝有mysql-client/mysql-devel,一樣須要執行yum刪除。
一個更好的辦法是一次刪除mysql開發的全部包
[root@www download]# yum remove mysql-*
二、下載mysql5.7,須要先檢查centos的系統位數
[root@www ~]#getconf LONG_BIT
[root@www ~]#getconf WORD_BIT
我這裏兩個顯示都是32,所以應該下載32版本(對應i686)。
到http://dev.mysql.com/downloads/mysql/這個地址下載最新穩定版本,centos對應選擇Red Hat…
[root@www download]# wget https://dev.mysql.com/get/Downloads/MySQL-5.7/mysql-community-common-5.7.10-1.el6.i686.rpm
[root@www download]# wget https://dev.mysql.com/get/Downloads/MySQL-5.7/mysql-community-libs-5.7.10-1.el6.i686.rpm
[root@www download]# wget https://dev.mysql.com/get/Downloads/MySQL-5.7/mysql-community-client-5.7.10-1.el6.i686.rpm
[root@www download]# wget https://dev.mysql.com/get/Downloads/MySQL-5.7/mysql-community-server-5.7.10-1.el6.i686.rpm
安裝依賴
[root@www download]# yum install -y libnuma*
分別安裝
[root@www download]# rpm -ivh mysql-community-common-5.7.10-1.el6.i686.rpm
[root@www download]# rpm -ivh mysql-community-libs-5.7.10-1.el6.i686.rpm
[root@www download]# rpm -ivh mysql-community-client-5.7.10-1.el6.i686.rpm
[root@www download]# rpm -ivh mysql-community-server-5.7.10-1.el6.i686.rpm
查看安裝信息
[root@www download]# yum list installed | grep ^mysql
mysql-community-client.i686 5.7.10-1.el6 installed
mysql-community-common.i686 5.7.10-1.el6 installed
mysql-community-libs.i686 5.7.10-1.el6 installed
mysql-community-server.i686 5.7.10-1.el6 installed
最後查看 mysql 版本
[root@www download]# mysql --version
mysql Ver 14.14 Distrib 5.7.10, for Linux (i686) using EditLine wrapper
看來真的已經正確安裝了。
檢查my.cnf
[root@www download]# vim /etc/my.cnf
1 # For advice on how to change settings please see
2 # http://dev.mysql.com/doc/refman/5.7/en/server-configuration-defaults.html
3
4 [mysqld]
5 #
6 # Remove leading # and set to the amount of RAM for the most important data
7 # cache in MySQL. Start at 70% of total RAM for dedicated server, else 10%.
8 # innodb_buffer_pool_size = 128M
9 #
10 # Remove leading # to turn on a very important data integrity option: loggin g
11 # changes to the binary log between backups.
12 # log_bin
13 #
14 # Remove leading # to set options mainly useful for reporting servers.
15 # The server defaults are faster for transactions and fast SELECTs.
16 # Adjust sizes as needed, experiment to find the optimal values.
17 # join_buffer_size = 128M
18 # sort_buffer_size = 2M
19 # read_rnd_buffer_size = 2M
20 datadir=/var/lib/mysql
21 socket=/var/lib/mysql/mysql.sock
22
datadir、socket位置查看
[root@www download]# stat /var/lib/mysql
File: "/var/lib/mysql"
Size: 4096 Blocks: 8 IO Block: 4096 目錄
Device: fd00h/64768d Inode: 2621666 Links: 5
Access: (0751/drwxr-x--x) Uid: ( 27/ mysql) Gid: ( 27/ mysql)
Access: 2015-12-28 01:10:54.855025003 +0800
Modify: 2015-11-30 03:48:49.000000000 +0800
Change: 2015-12-28 00:54:11.506460247 +0800
看來數據還在。
這下能夠啓動mysql了吧。
[root@www ~]# /etc/init.d/mysqld start
MySQL Daemon failed to start.
正在啓動 mysqld: [失敗]
提示失敗。先升級mysql配置
[root@www ~]# mysql_upgrade -u root –p
Enter password:
mysql_upgrade: Got error: 2002: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (2) while connecting to the MySQL server
Upgrade process encountered error and will not continue.
結果報錯,應該是'/var/lib/mysql/mysql.sock' 不存在。先生成一個
[root@www ~]# touch /var/lib/mysql/mysql.sock
仍是報錯。
查看mysqld的啓動日誌發現從5.1升級到5.7變化很大,報了幾個waring和Error
2015-12-28T13:41:08.287625Z 0 [Warning] TIMESTAMP with implicit DEFAULT value is deprecated. Please use --explicit_defaults_for_timestamp server option (see documentation for more details).
…
2015-12-28T13:41:09.316911Z 0 [Warning] System table 'plugin' is expected to be transactional.
2015-12-28T13:41:09.318169Z 0 [Warning] Gtid table is not ready to be used. Table 'mysql.gtid_executed' cannot be opened.
2015-12-28T13:41:09.318285Z 0 [Warning] Failed to set up SSL because of the following SSL library error: SSL context is not usable without certificate and private key…
2015-12-28T13:41:09.385341Z 0 [Warning] Failed to open optimizer cost constant tables
2015-12-28T13:41:09.386799Z 0 [ERROR] Fatal error: mysql.user table is damaged. Please run mysql_upgrade.
2015-12-28T13:41:09.386944Z 0 [ERROR] Aborting
5.7須要添加幾個系統表。
先以安全模式啓動mysqld守護進程。
[root@www ~]# mysqld_safe start
151228 22:10:42 mysqld_safe Logging to '/var/log/mysqld.log'.
151228 22:10:42 mysqld_safe Starting mysqld daemon with databases from /var/lib/mysql
151228 22:10:46 mysqld_safe mysqld from pid file /var/run/mysqld/mysqld.pid ended
最後mysqld進程好像沒有啓動成功…
查看3306端口
[root@www ~]# netstat -ano|grep 3306
[root@www ~]#
果真一無所得。安全進程並未啓動,如錯誤日誌所述,基本系統表缺失。初始化之
[root@www ~]# mysqld –initialize
2015-12-28T14:18:49.246041Z 0 [Warning] TIMESTAMP with implicit DEFAULT value is deprecated. Please use --explicit_defaults_for_timestamp server option (see documentation for more details).
2015-12-28T14:18:49.250859Z 0 [ERROR] --initialize specified but the data directory has files in it. Aborting.
2015-12-28T14:18:49.250941Z 0 [ERROR] Aborting
若是查看/etc/init.d/mysqld啓動項應知,mysqld --initialize命令是service mysqld start的一部份,若是 start的時候沒有發現data目錄則安裝之,發現錯誤則報錯…。故,上面的嘗試徒勞。
看來,它檢查到了原5.1的系統表,發現衝突之處。所以,應該將my.cnf下datadir/socket配置指定的存放位置移位。
[mysqld]
datadir=/var/lib/mysql5.7
socket=/var/lib/mysql5.7/mysql.sock#上面socket目錄放在[mysqld]模塊內,那麼[client]也須要指定socket位置,否則會報錯
[client]
socket=/var/lib/mysql5.7/mysql.sock
移動到了mysql5.7目錄。同時,將/etc/init.d/mysqld的47行配置進行修改
[root@www ~]# vim /etc/init.d/mysqld
…
get_mysql_option mysqld datadir "/var/lib/mysql5.7"
使它的datadir指向mysql5.7,根據上下文,mysql.sock的指向也變了,它也存放在mysql5.7目錄下面。
再次執行initialize命令。
[root@www ~]# mysqld –initialize
2015-12-28T14:30:42.853099Z 0 [Warning] TIMESTAMP with implicit DEFAULT value is deprecated. Please use --explicit_defaults_for_timestamp server option (see documentation for more details).
2015-12-28T14:30:46.950814Z 0 [Warning] InnoDB: New log files created, LSN=45790
2015-12-28T14:30:47.713023Z 0 [Warning] InnoDB: Creating foreign key constraint system tables.
2015-12-28T14:30:47.950677Z 0 [Warning] No existing UUID has been found, so we assume that this is the first time that this server has been started. Generating a new UUID: 965094c2-ad6f-11e5-8c8a-001641ad962e.
2015-12-28T14:30:47.999549Z 0 [Warning] Gtid table is not ready to be used. Table 'mysql.gtid_executed' cannot be opened.
2015-12-28T14:30:48.000932Z 1 [Note] A temporary password is generated for root@localhost: sfW2h2*Y55IS
查看工做目錄是否創建
[root@www ~]# ls /var/lib/mysql5.7
auto.cnf ibdata1 ib_logfile1 performance_schema
ib_buffer_pool ib_logfile0 mysql sys
有關[Warning] TIMESTAMP with implicit DEFAULT value is deprecated.Please use --explicit_defaults_for_timestamp server option (seedocumentation for more details).的警告查看http://dev.mysql.com/doc/refman/5.7/en/server-system-variables.html#sysvar_explicit_defaults_for_timestamp,這是個臨時啓動設置,未來會被廢棄,如今提醒你轉向新的mysql非標準sql行爲。
再次啓動mysqld安全模式
[root@www ~]# mysqld_safe start
查看端口沒有啓動,提示mysql5.7所在目錄權限
2015-12-28T15:32:06.227936Z 0 [ERROR] InnoDB: ./ib_logfile0 can't be opened in read-write mode.
改變 mysql5.7的全部者和權限爲用戶mysql
[root@www ~]# chown -R mysql: /var/lib/mysql5.7
[root@www ~]# chmod -R og+wr /var/lib/mysql5.7
[root@www ~]# ls -laZ /var/lib/mysql5.7drwxrwxrwx mysql mysql ? .
drwxr-xr-x root root ? ..
-rw-rw-rw- mysql mysql ? auto.cnf
-rw-rw-rw- mysql mysql ? ib_buffer_pool
-rw-rw-rw- mysql mysql ? ibdata1
-rw-rw-rw- mysql mysql ? ib_logfile0
-rw-rw-rw- mysql mysql ? ib_logfile1
drwxrwxrw- mysql mysql ? mysql
drwxrwxrw- mysql mysql ? performance_schema
drwxrwxrw- mysql mysql ? sys
再次啓動mysqld_safe start
[root@www ~]# mysqld_safe start
151229 00:40:40 mysqld_safe Logging to '/var/log/mysqld.log'.
151229 00:40:40 mysqld_safe Starting mysqld daemon with databases from /var/lib/mysql5.7
151229 00:40:43 mysqld_safe mysqld from pid file /var/run/mysqld/mysqld.pid ended
嗯,已經沒有錯誤了!中止 mysqld_safe
[root@www ~]# mysqld_safe stop
執行啓動 mysqld
[root@www ~]# /etc/init.d/mysqld start
正在啓動 mysqld: [肯定]
[root@www ~]# netstat -ano|grep 3306
tcp 0 0 :::3306 :::* LISTEN off (0.00/0/0)
正常啓動。
登錄mysql客戶端
[root@www ~]# mysql -uroot –p
Enter password:
ERROR 1045 (28000): Access denied for user 'root'@'localhost' (using password: NO)
這個在mysql5.7很是困擾,由於好像從mysql5.6開始,默認新安裝mysql,初始密碼不爲空,mysql會隨機生成一個。so,你須要本身從新設置一個。
與mysql5.6 不一樣, mysql.user下面,沒有password字段:
*************************** 1. row ***************************
Host: localhost
User: root
Select_priv: Y
Insert_priv: Y
Update_priv: Y
Delete_priv: Y
Create_priv: Y
Drop_priv: Y
Reload_priv: Y
Shutdown_priv: Y
Process_priv: Y
File_priv: Y
Grant_priv: Y
References_priv: Y
Index_priv: Y
Alter_priv: Y
Show_db_priv: Y
Super_priv: Y
Create_tmp_table_priv: Y
Lock_tables_priv: Y
Execute_priv: Y
Repl_slave_priv: Y
Repl_client_priv: Y
Create_view_priv: Y
Show_view_priv: Y
Create_routine_priv: Y
Alter_routine_priv: Y
Create_user_priv: Y
Event_priv: Y
Trigger_priv: Y
Create_tablespace_priv: Y
ssl_type:
ssl_cipher:
x509_issuer:
x509_subject:
max_questions: 0
max_updates: 0
max_connections: 0
max_user_connections: 0
plugin: mysql_native_password
authentication_string: *D3BFB08382EB0AB95519518E0BFF147C0A4D03E6
password_expired: Y
password_last_changed: 2015-12-28 22:31:03
password_lifetime: NULL
account_locked: N
只有authentication_string,能夠看到,初始階段,它不爲空。
由於無法從mysql客戶端進入,所以,只能先關閉mysqld 進程,啓動mysqld_safe,指定--skip-grant-tables。
[root@www ~]# /etc/init.d/mysqld stop
中止 mysqld: [肯定]
[root@www ~]# mysqld_safe --skip-grant-tables151229 21:29:14 mysqld_safe Logging to '/var/log/mysqld.log'.
151229 21:29:14 mysqld_safe Starting mysqld daemon with databases from /var/lib/mysql5.7
mysqld守護進程打開成功。新打開一個terminal window,進入mysql client。
[root@www ~]# mysql
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 2
Server version: 5.7.10 MySQL Community Server (GPL)Copyright (c) 2000, 2015, Oracle and/or its affiliates. All rights reserved.
Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
mysql> use mysql
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -ADatabase changed
mysql> UPDATE mysql.user SET authentication_string=PASSWORD('123456') WHERE User='root';
Query OK, 1 row affected, 1 warning (0.00 sec)
Rows matched: 1 Changed: 1 Warnings: 1mysql> flush privileges;
Query OK, 0 rows affected (0.00 sec)mysql> exit
Bye
在新窗口中退出mysqld_safe進程,
[root@www ~]# ps -A|grep mysql
3758 pts/1 00:00:00 mysqld_safe
3939 pts/1 00:00:00 mysqld
[root@www ~]# kill -9 3758 3939
在mysqld_safe所在窗口(terminal),能夠看到mysqld_safe已殺死。
如今嘗試正常開啓mysqld,並進入mysql client。
[root@www ~]# /etc/init.d/mysqld start
正在啓動 mysqld: [肯定]
[root@www ~]# mysql -uroot –p
…
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 3
Server version: 5.7.10Copyright (c) 2000, 2015, Oracle and/or its affiliates. All rights reserved.
Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
成功。
檢查自啓動項
[root@www download]# chkconfig –list
NetworkManager 0:關閉 1:關閉 2:啓用 3:啓用 4:啓用 5:啓用 6:關閉
…
multipathd 0:關閉 1:關閉 2:關閉 3:關閉 4:關閉 5:關閉 6:關閉
mysqld 0:關閉 1:關閉 2:關閉 3:關閉 4:關閉 5:關閉 6:關閉
netconsole 0:關閉 1:關閉 2:關閉 3:關閉 4:關閉 5:關閉 6:關閉
可見其沒有開啓,故開啓之
[root@www ~]# chkconfig --add mysqld
如今再來看mysqld的啓動項:
…
mysqld 0:關閉 1:關閉 2:啓用 3:啓用 4:啓用 5:啓用 6:關閉
…
已經2 3 4 5級別level啓動(依/ect/init.d/mysqld啓動腳本設定)。
再有選擇地導入以前保存的sql備份(略)。
這裏須要提醒的是, mysql5.7增長了一個嚴格模式,它認爲命令行的操做都是不安全的,所以須要指定客戶端(命令行)鏈接的有效期。若是沒有,它會查看session狀態,一旦檢查到其它操做,當即會提醒你更改密碼。所以最好在退出客戶端前經過下面語句更改密碼。
mysql> ALTER USER USER() IDENTIFIED BY 'new_password';
而後在my.cnf增長一個客戶端(命令行)有效期,固然能夠設置永不過時。
至此結束。