Details
-
Bug
-
Status: Open (View Workflow)
-
Major
-
Resolution: Unresolved
-
2.7.0
-
None
-
None
-
MySQL Server using caching_sha2_password
JDBC URL uses localSocket and SSL disabled
Description
When connecting with caching_sha2_password through a Unix socket and SSL disabled, Connector/J requests the RSA public key during full authentication. The server treats a Unix socket as a secure connection and expects the password in cleartext, so it returns "Access denied" instead of the public key.
This happens only when the server-side SHA-256 cache is empty (for example after mysqld has been restarted, or before that account has authenticated successfully). If the cache is already populated, fast authentication succeeds and the bug is hidden.
The same bug was fixed in MariaDB Connector/Node.js:
https://github.com/mariadb-corporation/mariadb-connector-nodejs/issues/326
https://github.com/mariadb-corporation/mariadb-connector-nodejs/pull/327
Steps to reproduce
1. Create a user with caching_sha2_password.
2. Restart mysqld so the in-memory SHA-256 cache is empty.
3. Connect with Connector/J over the Unix socket, with SSL disabled and allowPublicKeyRetrieval=true.
4. Do not connect successfully with another client first. A successful mysql CLI login over the same socket fills the cache, and the following JDBC attempt then succeeds.
Expected
On auth result 0x04 (full authentication), the driver sends the password in cleartext, as it already does when SSL is enabled.
Actual
CachingSha2PasswordPlugin sends the cleartext password only when SSL is enabled. Otherwise it requests the RSA public key (byte 0x02). Over a Unix socket the server responds with an error packet, and the driver throws:
java.sql.SQLInvalidAuthorizationSpecException: Could not connect to address=(host=localhost)(port=3306)(type=master) : Could not connect: Access denied for user '...'@'localhost' (using password: YES)
|
Caused by: java.sql.SQLException: Could not connect: Access denied for user '...'@'localhost' (using password: YES)
|
at org.mariadb.jdbc.internal.com.send.authentication.Sha256PasswordPlugin.readPublicKeyFromSocket(Sha256PasswordPlugin.java:90)
|
at org.mariadb.jdbc.internal.com.send.authentication.CachingSha2PasswordPlugin.process(CachingSha2PasswordPlugin.java:199)
|
In 3.5.10 the branch is still SSL-only (case 0x04, sslMode != SslMode.DISABLE sends the cleartext password; the else branch requests the public key):
https://github.com/mariadb-corporation/mariadb-connector-j/blob/3.5.10/src/main/java/org/mariadb/jdbc/plugin/authentication/standard/CachingSha2PasswordPlugin.java
Workaround
Connect once with the mysql client over the same Unix socket so the server caches the account. Later JDBC connections can then use fast authentication. The cache is per mysqld process and is cleared on restart.