Use TLS/SSL for the QCBM Recovery Runner Database Connection
The QCBM Recovery Runner can use encrypted MySQL/MariaDB connection settings when the target database requires TLS or when database traffic crosses a network you do not want to leave unencrypted.
TLS settings apply to the Recovery Runner's database connection. They are separate from HTTPS used to protect the browser session with the runner.
Enable Encrypted Database Connection Settings
In 2. Database Setup, enable Use encrypted database connection settings. QCBM then exposes the TLS fields used by the PHP PDO MySQL driver.
TLS CA File
Use TLS CA file when the database service provides a certificate-authority file that should be trusted for the server certificate. Enter the server path to the CA file accessible to PHP on the recovery destination.
TLS Client Certificate and Key
Some database services require mutual TLS. In that case provide the paths for TLS client certificate and TLS client key supplied for the database account.
Do not upload or invent certificate material just to populate these fields. Use only the files required by the database provider and protect their permissions on disk.
Verify Database Server Certificate
Verify database server certificate is enabled by default when TLS fields are shown. Leave verification enabled whenever the database service supports normal certificate validation.
Disabling verification weakens protection against connecting to the wrong server. Treat any need to disable it as an environment-specific exception that should be understood and corrected where possible.
When TLS Matters Most
TLS is especially important when the database runs on another server, a managed database service, or any route where traffic leaves the local host/private trusted boundary. A local Unix socket does not traverse the network and has different transport characteristics.
Test the TLS Connection
- Enter the normal database host/port or socket, database name, username, password, and prefix.
- Enable encrypted database settings.
- Enter the CA/client certificate/key paths required by the provider.
- Leave server-certificate verification enabled unless you have a specific documented reason not to.
- Select Test Database.
Do not begin recovery until the test succeeds. TLS errors can come from wrong file paths, unreadable certificate files, a hostname/certificate mismatch, unsupported server settings, or credentials that are valid only for a different connection method.
Keep Browser HTTPS and Database TLS Separate
Use HTTPS for the Recovery Runner page whenever possible even when the database connection also uses TLS. HTTPS protects the PIN and database credentials between your browser and the recovery server; database TLS protects traffic between PHP and the database server.
After Recovery
Confirm the restored Joomla site's own database configuration matches the connection model required in production. The Recovery Runner's successful test proves the recovery connection worked; the restored site's configuration must also be valid for normal Joomla requests.
Community Discussion
Want to compare workflows, share practical tips, or discuss how you use this QCBM feature? Visit the QC Backup Manager Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.