Details
-
Task
-
Status: Closed (View Workflow)
-
Critical
-
Resolution: Fixed
-
2.3.0
-
None
Description
MySQL 8.0 introduced a new authentication plugin "caching_sha2_password" plugin, which is enabled by default and will be used as standard plugin:
Workflow:
1) Server sends scramble packet
2) Clients generates a sha256 hashed authentication string with the following mechanism:
digest1= sha256(password)
digest2= sha256(digest1)
digest3= sha256(digest2, scramble)
digest4= xor(digest1, digest3)
3) Client sends digest4 as authentication string
On success server sends a packet with length=1 and content=3. In case the password was not cached, server requires same authentication mechanism as in sha256_password with a little difference, the padding algorithm is PKCS1 v1.5 padding instead of OAEP.
Attachments
Issue Links
- relates to
-
CONJ-327 Handle sha256_password plugin
-
- Closed
-
-
CONJS-76 Implement sha256_password support
-
- Closed
-
-
CONJS-77 Implement caching_sha256_password support
-
- Closed
-
-
MDEV-9804 Implement a caching_sha256_password plugin
-
- Open
-
-
MXS-1325 Add sha256_password authenticator
-
- Closed
-
-
ODBC-241 Add parameter that corresponds to MYSQL_SERVER_PUBLIC_KEY option from MariaDB Connector/C
-
- Closed
-
-
CONC-229 SHA256 authentication plugin
-
- Closed
-
-
CONC-312 Implement caching_sha2_password plugin
-
- Closed
-
Activity
Fix Version/s | 2.5.0 [ 23257 ] |
Fix Version/s | 2.5.0 [ 23257 ] |
Fix Version/s | 2.5.0 [ 23257 ] |
Status | Open [ 1 ] | In Progress [ 3 ] |
issue.field.resolutiondate | 2019-09-27 09:37:34.0 | 2019-09-27 09:37:34.453 |
Resolution | Fixed [ 1 ] | |
Status | In Progress [ 3 ] | Closed [ 6 ] |
Workflow | MariaDB v3 [ 91016 ] | MariaDB v4 [ 128395 ] |