A.1: Where can I find documentation that addresses security issues for MySQL?
A.2: What is the default authentication plugin in MySQL 5.7?
A.3: Does MySQL 5.7 have native support for SSL?
A.4: Is SSL support built into MySQL binaries, or must I recompile the binary myself to enable it?
A.5: Does MySQL 5.7 have built-in authentication against LDAP directories?
A.6: Does MySQL 5.7 include support for Roles Based Access Control (RBAC)?
Questions and Answers
The best place to start is Chapter 1, Security.
Other portions of the MySQL Documentation which you may find useful with regard to specific security concerns include the following:
There is also the Secure Deployment Guide, which provides procedures for deploying a generic binary distribution of MySQL Enterprise Edition Server with features for managing the security of your MySQL installation.
The default authentication plugin in MySQL 5.7 is
mysql_native_password. For information about
this plugin, see
Section 6.1.1, “Native Pluggable Authentication”. For general
information about pluggable authentication and other available
authentication plugins, see
Section 4.13, “Pluggable Authentication”, and
Section 6.1, “Authentication Plugins”.
Most 5.7 binaries have support for SSL connections between the client and server. See Chapter 5, Using Encrypted Connections.
You can also tunnel a connection using SSH, if (for example) the client application does not support SSL connections. For an example, see Section 5.5, “Connecting to MySQL Remotely from Windows with SSH”.
Most 5.7 binaries have SSL enabled for client/server connections that are secured, authenticated, or both. See Chapter 5, Using Encrypted Connections.
The Enterprise edition includes a PAM Authentication Plugin that supports authentication against an LDAP directory.
Not at this time.