A fresh database server is working but not yet hardened: it may contain a test database, anonymous accounts and, on some systems, listen on every network interface. A few minutes of setup removes those risks. The steps are written for MariaDB, the default on Debian, Ubuntu and AlmaLinux; notes for MySQL are included.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
Step 1: Run the secure installation script
sudo mariadb-secure-installation
(On MySQL, or older MariaDB, the command is sudo mysql_secure_installation.) Suggested answers:
| Question | Answer | Why |
|---|---|---|
| Enter current password for root | Press Enter | A new install has none |
| Switch to unix_socket authentication | n if it says root is already protected, otherwise Y | Lets only the Linux root user log in as database root, with no password to steal |
| Change the root password | n (with socket login) or Y | Socket login doesn't need one |
| Remove anonymous users | Y | Anyone could log in without a name otherwise |
| Disallow root login remotely | Y | Root should only connect from the server itself |
| Remove test database | Y | It is open to all users |
| Reload privilege tables | Y | Applies the changes now |
Afterwards, open the database shell as root with sudo mariadb (no password needed, thanks to socket authentication).
Step 2: Give each application its own user
Never let a website connect as root. Create a database and a user that can only touch that database:
sudo mariadb
Then, at the MariaDB [(none)]> prompt:
CREATE DATABASE shopdb CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; CREATE USER 'shopuser'@'localhost' IDENTIFIED BY 'a-long-random-password'; GRANT ALL PRIVILEGES ON shopdb.* TO 'shopuser'@'localhost'; FLUSH PRIVILEGES; EXIT;
If the site is hacked, the attacker only reaches this one database. Generate the password with openssl rand -base64 24.
Review existing accounts at any time:
SELECT User, Host, plugin FROM mysql.user;
Remove any you don't recognise with DROP USER 'name'@'host';.
Step 3: Keep the database off the internet
Check which address the server listens on:
sudo ss -tlnp | grep -E '3306|mariadb|mysqld'
You want to see 127.0.0.1:3306. If you see 0.0.0.0:3306 or *:3306, set the bind address:
- Ubuntu/Debian:
/etc/mysql/mariadb.conf.d/50-server.cnf - AlmaLinux/Rocky:
/etc/my.cnf.d/mariadb-server.cnf - MySQL on Ubuntu:
/etc/mysql/mysql.conf.d/mysqld.cnf
Under the [mysqld] section add or change:
bind-address = 127.0.0.1
Then restart with sudo systemctl restart mariadb (or mysql). Also make sure port 3306 is not allowed in your firewall.
Step 4: Connect remotely the safe way (SSH tunnel)
To use a desktop tool such as HeidiSQL, DBeaver or MySQL Workbench, don't open port 3306. Tunnel through SSH instead; most of these tools have an SSH tunnel option built in. From a terminal:
ssh -L 3307:127.0.0.1:3306 [email protected]
While that window stays open, point your database tool at host 127.0.0.1, port 3307, with your database user and password.
If another server truly must connect directly, create a user limited to that server's IP ('appuser'@'198.51.100.20'), allow only that IP to port 3306 in the firewall, change bind-address to 0.0.0.0, and require TLS for that user.
More good practice
- phpMyAdmin: avoid installing it on a public URL. If you must, put it behind HTTPS plus an extra password or IP restriction in Nginx.
- Updates: database security fixes arrive through normal package updates. See automatic security updates.
- Backups: dump databases every day. See How to Back Up Your VPS.
- MySQL's password component: on MySQL, the setup script offers the VALIDATE PASSWORD component, which rejects weak passwords. Choosing the medium level is a sensible default.
Common problems
Access denied for user 'root'@'localhost'when runningmariadb: usesudo mariadb; socket login needs the Linux root user.- A website can't connect after hardening: the app must use host
localhost(or127.0.0.1) and its own user, not root. - MariaDB won't start after editing the config: check
sudo journalctl -u mariadb -n 50for the line with the typo.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer