What it means
Each account names an authentication plugin, the method used to prove the password, and the client has to run the matching half of it. When the server asks for a method the client library doesn’t include, and it can’t find a plugin file for it either, the client stops with error 2059 before sending the password. The path in the message is where it looked.
The usual cases:
caching_sha2_password, the default for new accounts since MySQL 8.0, with a client or driver built on MySQL 5.7-era libraries: old command-line clients, old GUI tools, old language drivers.- MariaDB’s
ed25519(the client side is calledclient_ed25519) with a MySQL client, which doesn’t have it. - A wrong
--plugin-dir(or a broken installation), so even a client that has the plugin as a file can’t find it.
MariaDB’s client library says it differently, with error 1045:
Plugin caching_sha2_password could not be loaded: ….
Common causes
- An outdated client or driver connecting to MySQL 8 with an account that uses
caching_sha2_password. - A MySQL client connecting to a MariaDB account set up with
ed25519. - A client library installed without its plugin directory, or pointed at the wrong one.
How to fix it
Update the client or driver
Any client built against MySQL 8 libraries, and current MariaDB connectors, support
caching_sha2_password. For MariaDB’s ed25519, use a MariaDB client or connector, which include
client_ed25519.
Or change the account’s method
On MariaDB, move an ed25519 account to the method every client supports:
ALTER USER 'app'@'%' IDENTIFIED VIA mysql_native_password USING PASSWORD('<password>');
On MySQL, the old advice was ALTER USER … IDENTIFIED WITH mysql_native_password. That still works
on 8.0, but MySQL 8.4 has the plugin turned off
(error 1524) and 9.0 removes it, so
updating the client is the lasting fix.
“Authentication requires secure connection”: error 2061
A client that has caching_sha2_password can still fail the first time an account signs in
after the server starts (before its password is cached), when the connection isn’t encrypted and
the client hasn’t got the server’s RSA public key:
ERROR 2061 (HY000): Authentication plugin 'caching_sha2_password' reported error: Authentication requires secure connection.
Connect with TLS, or let the client fetch the key: mysql --get-server-public-key, or your
driver’s equivalent option. Once one sign-in has succeeded, later ones work without it until the
server restarts.
Reproduce it
The MySQL 8.4.11 client, connecting to a temporary MariaDB 11.4.13 container (removed afterwards)
whose account was created with IDENTIFIED VIA ed25519:
mysql -h host.docker.internal -P33992 -useo_ed -p -e 'select current_user()'
ERROR 2059 (HY000): Authentication plugin 'client_ed25519' cannot be loaded: /usr/lib64/mysql/plugin/client_ed25519.so: cannot open shared object file: No such file or directory
The mariadb client signed in to the same account. After
ALTER USER … IDENTIFIED VIA mysql_native_password, the MySQL client did too.
The MariaDB 11.4.13 client, pointed at an empty plugin directory and connecting to a MySQL 8.4
account that uses caching_sha2_password:
ERROR 1045 (28000): Plugin caching_sha2_password could not be loaded: /nonexistent/caching_sha2_password.so: cannot open shared object file: No such file or directory
The MySQL 8.4 client, with TLS turned off (--ssl-mode=DISABLED), to a new MySQL 8.4 account:
ERROR 2061 (HY000): Authentication plugin 'caching_sha2_password' reported error: Authentication requires secure connection.
With --get-server-public-key it signed in, and afterwards it signed in without the option.
The exact 'caching_sha2_password' cannot be loaded wording needs a client from before MySQL 8.0,
which wasn’t available here; it has the same cause and fixes as the client_ed25519 case above.
In Inlet
Inlet connects through its own MySQL driver, not a client library with plugin files, and signs in
with caching_sha2_password (with or without TLS, fetching the server’s key when needed),
mysql_native_password and sha256_password. When a server asks for a method Inlet can’t use,
such as MariaDB’s ed25519, the connection window says which, and links to this page.