简单记录下
先生成SSL证书
# 生成CA。common name可以设置为MariaDB CA
openssl genrsa 2048 > ca-key.pem
openssl req -new -x509 -nodes -days 730 -key ca-key.pem -out ca-cert.pem
# 生成服务器证书。common name可以设置为MariaDB Server
openssl req -newkey rsa:2048 -days 730 -nodes -keyout server-key.pem -out server-req.pem
openssl rsa -in server-key.pem -out server-key.