> For the complete documentation index, see [llms.txt](https://mariadb.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mariadb.com/docs/server/reference/clientserver-protocol/1-connecting/sha256_password-plugin.md).

# Connecting via sha256\_password

## Overview

`SHA256` authentication possible exchanges:

* If connection uses SSL (SSLRequest Packet sent):
  * Client sends a [clear password answer](#client-clear-password-answer).
* Else:
  * If client doesn't know server RSA public key:
    * Client sends a [public key request](#public-key-request).
    * Server sends a [public key response](#public-key-response).
  * Client sends an [RSA encrypted password](#rsa-encrypted-password).
  * Ends with server sending either [OK\_Packet](/docs/server/reference/clientserver-protocol/4-server-response-packets/ok_packet.md) , [ERR\_Packet](/docs/server/reference/clientserver-protocol/4-server-response-packets/err_packet.md).

## Authentication

### Client Clear Password Answer

* [string\<NUL>](/docs/server/reference/clientserver-protocol/protocol-data-types.md#null-terminated-strings) password without encryption.

### Public Key Request

* [byte<1>](/docs/server/reference/clientserver-protocol/protocol-data-types.md#fixed-length-bytes) fixed `0x01` value.

### Public Key Response

* [byte<1>](/docs/server/reference/clientserver-protocol/protocol-data-types.md#fixed-length-bytes) fixed `0x01` value.
* [byte\<EOF>](/docs/server/reference/clientserver-protocol/protocol-data-types.md#end-of-file-length-bytes) public key data.

### RSA Encrypted Password

* [byte<256>](/docs/server/reference/clientserver-protocol/protocol-data-types.md#fixed-length-bytes) RSA encrypted password.

RSA encrypted value of `XOR`(password, seed) using server public key (`RSA_PKCS1_OAEP_PADDING`).

<sub>*This page is licensed: CC BY-SA / Gnu FDL*</sub>

{% @marketo/form formId="4316" %}
