{"record":{"id":"d60080f525efdc78","repo":"go-sql-driver/mysql","slug":"this-user-requires-old-password-authentication-if","errorCode":null,"errorMessage":"this user requires old password authentication. If you still want to use it, please add 'allowOldPasswords=1' to your DSN. See also https://github.com/go-sql-driver/mysql/wiki/old_passwords","messagePattern":"this user requires old password authentication\\. If you still want to use it, please add 'allowOldPasswords=1' to your DSN\\. See also https://github\\.com/go-sql-driver/mysql/wiki/old_passwords","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"errors.go","lineNumber":24,"sourceCode":"// License, v. 2.0. If a copy of the MPL was not distributed with this file,\n// You can obtain one at http://mozilla.org/MPL/2.0/.\n\npackage mysql\n\nimport (\n\t\"errors\"\n\t\"fmt\"\n\t\"log\"\n\t\"os\"\n)\n\n// Various errors the driver might return. Can change between driver versions.\nvar (\n\tErrInvalidConn       = errors.New(\"invalid connection\")\n\tErrMalformPkt        = errors.New(\"malformed packet\")\n\tErrNoTLS             = errors.New(\"TLS requested but server does not support TLS\")\n\tErrCleartextPassword = errors.New(\"this user requires clear text authentication. If you still want to use it, please add 'allowCleartextPasswords=1' to your DSN\")\n\tErrNativePassword    = errors.New(\"this user requires mysql native password authentication\")\n\tErrOldPassword       = errors.New(\"this user requires old password authentication. If you still want to use it, please add 'allowOldPasswords=1' to your DSN. See also https://github.com/go-sql-driver/mysql/wiki/old_passwords\")\n\tErrUnknownPlugin     = errors.New(\"this authentication plugin is not supported\")\n\tErrOldProtocol       = errors.New(\"MySQL server does not support required protocol 41+\")\n\tErrPktSync           = errors.New(\"commands out of sync. You can't run this command now\")\n\tErrPktSyncMul        = errors.New(\"commands out of sync. Did you run multiple statements at once?\")\n\tErrPktTooLarge       = errors.New(\"packet for query is too large. Try adjusting the `Config.MaxAllowedPacket`\")\n\tErrBusyBuffer        = errors.New(\"busy buffer\")\n\n\t// errBadConnNoWrite is used for connection errors where nothing was sent to the database yet.\n\t// If this happens first in a function starting a database interaction, it should be replaced by driver.ErrBadConn\n\t// to trigger a resend. Use mc.markBadConn(err) to do this.\n\t// See https://github.com/go-sql-driver/mysql/pull/302\n\terrBadConnNoWrite = errors.New(\"bad connection\")\n)\n\nvar defaultLogger = Logger(log.New(os.Stderr, \"[mysql] \", log.Ldate|log.Ltime))\n\n// Logger is used to log critical error messages.","sourceCodeStart":6,"sourceCodeEnd":42,"githubUrl":"https://github.com/go-sql-driver/mysql/blob/03d76c7e07908e255ce62d126d07ede3f2365d86/errors.go#L6-L42","documentation":"ErrOldPassword is returned from auth() (auth.go:285) when the server requires the deprecated mysql_old_password (pre-4.1) plugin and allowOldPasswords is not set. The old algorithm is cryptographically broken, so the driver forces explicit opt-in.","triggerScenarios":"Connecting to a very old MySQL server (< 4.1) or to an account whose password was stored using the pre-4.1 short-hash format, without allowOldPasswords=1 in the DSN.","commonSituations":"Legacy appliances/embedded MySQL; databases migrated from ancient versions that retained old-format password hashes; connecting to a server with old_passwords=1 set globally.","solutions":["Upgrade the account password to the 4.1+ format (SET PASSWORD ... / ALTER USER) and use mysql_native_password or caching_sha2_password.","Upgrade the server to a supported version that no longer offers mysql_old_password.","As a last resort add allowOldPasswords=1 to the DSN, understanding it is insecure and only works over trusted/TLS links."],"exampleFix":"// before\ndsn := \"user:pass@tcp(legacy:3306)/db\"\n// -> ErrOldPassword\n\n// after (preferred): on the server, modernize the hash\n//   ALTER USER 'user'@'%' IDENTIFIED WITH mysql_native_password BY 'pass';\n// or (temporary, insecure) opt in client-side:\ndsn := \"user:pass@tcp(legacy:3306)/db?allowOldPasswords=1\"","handlingStrategy":"validation","validationCode":"// Legacy servers: only opt in if you must, and always over TLS/unix.\ndsn := \"user:pass@unix(/tmp/mysql.sock)/db\"\nif legacyOldPasswordServer {\n    dsn += \"?allowOldPasswords=1\"\n}","typeGuard":"func isOldPasswordRequired(err error) bool {\n    return errors.Is(err, mysql.ErrOldPassword)\n}","tryCatchPattern":"if errors.Is(err, mysql.ErrOldPassword) {\n    // modernize the account password, or (insecurely) opt in:\n    //   ...?allowOldPasswords=1  -- only over a trusted transport\n}","preventionTips":["Upgrade legacy accounts to 4.1+ password hashes.","Treat mysql_old_password as a decommission blocker, not a steady state.","Never use allowOldPasswords=1 over plaintext TCP."],"tags":["authentication","security","legacy","config"],"backgroundTag":null,"analyzedSha":"03d76c7e07908e255ce62d126d07ede3f2365d86","analyzedAt":"2026-08-07T10:39:17.340Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}