Uploaded image for project: 'MariaDB Connector/J'
  1. MariaDB Connector/J
  2. CONJ-1372

caching_sha2_password full authentication fails over a Unix socket when SSL is disabled

    XMLWordPrintable

Details

    • Bug
    • Status: Open (View Workflow)
    • Major
    • Resolution: Unresolved
    • 2.7.0
    • None
    • MySQL compatibility
    • None
    • MySQL Server using caching_sha2_password
      JDBC URL uses localSocket and SSL disabled

    Description

      When connecting with caching_sha2_password through a Unix socket and SSL disabled, Connector/J requests the RSA public key during full authentication. The server treats a Unix socket as a secure connection and expects the password in cleartext, so it returns "Access denied" instead of the public key.
      This happens only when the server-side SHA-256 cache is empty (for example after mysqld has been restarted, or before that account has authenticated successfully). If the cache is already populated, fast authentication succeeds and the bug is hidden.

      The same bug was fixed in MariaDB Connector/Node.js:
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/issues/326
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/pull/327

      Steps to reproduce

      1. Create a user with caching_sha2_password.
      2. Restart mysqld so the in-memory SHA-256 cache is empty.
      3. Connect with Connector/J over the Unix socket, with SSL disabled and allowPublicKeyRetrieval=true.
      4. Do not connect successfully with another client first. A successful mysql CLI login over the same socket fills the cache, and the following JDBC attempt then succeeds.

      Expected

      On auth result 0x04 (full authentication), the driver sends the password in cleartext, as it already does when SSL is enabled.

      Actual

      CachingSha2PasswordPlugin sends the cleartext password only when SSL is enabled. Otherwise it requests the RSA public key (byte 0x02). Over a Unix socket the server responds with an error packet, and the driver throws:

      java.sql.SQLInvalidAuthorizationSpecException: Could not connect to address=(host=localhost)(port=3306)(type=master) : Could not connect: Access denied for user '...'@'localhost' (using password: YES)
      Caused by: java.sql.SQLException: Could not connect: Access denied for user '...'@'localhost' (using password: YES)
              at org.mariadb.jdbc.internal.com.send.authentication.Sha256PasswordPlugin.readPublicKeyFromSocket(Sha256PasswordPlugin.java:90)
              at org.mariadb.jdbc.internal.com.send.authentication.CachingSha2PasswordPlugin.process(CachingSha2PasswordPlugin.java:199)
      

      In 3.5.10 the branch is still SSL-only (case 0x04, sslMode != SslMode.DISABLE sends the cleartext password; the else branch requests the public key):
      https://github.com/mariadb-corporation/mariadb-connector-j/blob/3.5.10/src/main/java/org/mariadb/jdbc/plugin/authentication/standard/CachingSha2PasswordPlugin.java

      Workaround

      Connect once with the mysql client over the same Unix socket so the server caches the account. Later JDBC connections can then use fast authentication. The cache is per mysqld process and is cleared on restart.

      Attachments

        Activity

          People

            diego dupin Diego Dupin
            w-kudo 工藤航
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.