go-sql-driver/mysql · error
this user requires old password authentication. If you…
Error message
this user requires old password authentication. If you still want to use it, please add 'allowOldPasswords=1' to your DSN. See also https://github.com/go-sql-driver/mysql/wiki/old_passwords
What it means
ErrOldPassword is returned from auth() (auth.go:285) when the server requires the deprecated mysql_old_password (pre-4.1) plugin and allowOldPasswords is not set. The old algorithm is cryptographically broken, so the driver forces explicit opt-in.
Solutions
- Upgrade the account password to the 4.1+ format (SET PASSWORD ... / ALTER USER) and use mysql_native_password or caching_sha2_password.
- Upgrade the server to a supported version that no longer offers mysql_old_password.
- As a last resort add allowOldPasswords=1 to the DSN, understanding it is insecure and only works over trusted/TLS links.
Example fix
// before dsn := "user:pass@tcp(legacy:3306)/db" // -> ErrOldPassword // after (preferred): on the server, modernize the hash // ALTER USER 'user'@'%' IDENTIFIED WITH mysql_native_password BY 'pass'; // or (temporary, insecure) opt in client-side: dsn := "user:pass@tcp(legacy:3306)/db?allowOldPasswords=1"
Defensive patterns
Strategy: validation
Validate before calling
// Legacy servers: only opt in if you must, and always over TLS/unix.
dsn := "user:pass@unix(/tmp/mysql.sock)/db"
if legacyOldPasswordServer {
dsn += "?allowOldPasswords=1"
} Type guard
func isOldPasswordRequired(err error) bool {
return errors.Is(err, mysql.ErrOldPassword)
} Try / catch
if errors.Is(err, mysql.ErrOldPassword) {
// modernize the account password, or (insecurely) opt in:
// ...?allowOldPasswords=1 -- only over a trusted transport
} Prevention
- Upgrade legacy accounts to 4.1+ password hashes.
- Treat mysql_old_password as a decommission blocker, not a steady state.
- Never use allowOldPasswords=1 over plaintext TCP.
When it happens
Trigger: Connecting to a very old MySQL server (< 4.1) or to an account whose password was stored using the pre-4.1 short-hash format, without allowOldPasswords=1 in the DSN.
Common situations: Legacy appliances/embedded MySQL; databases migrated from ancient versions that retained old-format password hashes; connecting to a server with old_passwords=1 set globally.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- this user requires clear text authentication. If you still…
- key ' ' is reserved
- this authentication plugin is not supported
- this user requires mysql native password authentication
- unexpected resp from server for caching_sha2_password…
AI-assisted analysis of go-sql-driver/mysql@03d76c7e07 (2026-08-07).
Data as JSON: /api/errors/d60080f525efdc78.
Report an issue: GitHub.
Appendix: source
Thrown at errors.go:24
// License, v. 2.0. If a copy of the MPL was not distributed with this file,
// You can obtain one at http://mozilla.org/MPL/2.0/.
package mysql
import (
"errors"
"fmt"
"log"
"os"
)
// Various errors the driver might return. Can change between driver versions.
var (
ErrInvalidConn = errors.New("invalid connection")
ErrMalformPkt = errors.New("malformed packet")
ErrNoTLS = errors.New("TLS requested but server does not support TLS")
ErrCleartextPassword = errors.New("this user requires clear text authentication. If you still want to use it, please add 'allowCleartextPasswords=1' to your DSN")
ErrNativePassword = errors.New("this user requires mysql native password authentication")
ErrOldPassword = errors.New("this user requires old password authentication. If you still want to use it, please add 'allowOldPasswords=1' to your DSN. See also https://github.com/go-sql-driver/mysql/wiki/old_passwords")
ErrUnknownPlugin = errors.New("this authentication plugin is not supported")
ErrOldProtocol = errors.New("MySQL server does not support required protocol 41+")
ErrPktSync = errors.New("commands out of sync. You can't run this command now")
ErrPktSyncMul = errors.New("commands out of sync. Did you run multiple statements at once?")
ErrPktTooLarge = errors.New("packet for query is too large. Try adjusting the `Config.MaxAllowedPacket`")
ErrBusyBuffer = errors.New("busy buffer")
// errBadConnNoWrite is used for connection errors where nothing was sent to the database yet.
// If this happens first in a function starting a database interaction, it should be replaced by driver.ErrBadConn
// to trigger a resend. Use mc.markBadConn(err) to do this.
// See https://github.com/go-sql-driver/mysql/pull/302
errBadConnNoWrite = errors.New("bad connection")
)
var defaultLogger = Logger(log.New(os.Stderr, "[mysql] ", log.Ldate|log.Ltime))
// Logger is used to log critical error messages.View on GitHub (pinned to 03d76c7e07)