# Authentication Plugin - mysql\_old\_password

The `mysql_old_password` authentication plugin is the default authentication plugin that is used for an account created when no authentication plugin is explicitly mentioned and [old\_passwords=1](https://mariadb.com/docs/server/server-management/variables-and-modes/server-system-variables#old_passwords) is set. It uses the pre-MySQL 4.1 password hashing algorithm, which is also used by the [OLD\_PASSWORD()](https://mariadb.com/docs/server/reference/sql-functions/secondary-functions/encryption-hashing-and-compression-functions/old_password) function and by the [PASSWORD()](https://mariadb.com/docs/server/reference/sql-functions/secondary-functions/encryption-hashing-and-compression-functions/password) function when `old_passwords=1` is set.

{% hint style="danger" %}
It is not recommended to use the `mysql_old_password` authentication plugin for new installations. The password hashing algorithm is no longer secure, and the plugin is primarily provided for backward compatibility. The [ed25519](https://mariadb.com/docs/server/reference/plugins/authentication-plugins/authentication-plugin-ed25519) authentication plugin is a more modern authentication plugin that provides simple password authentication.
{% endhint %}

## Installing the Plugin

The `mysql_old_password` authentication plugin is statically linked into the server, so no installation is necessary.

## Creating Users

The easiest way to create a user account with the `mysql_old_password` authentication plugin is to make sure that [old\_passwords=1](https://mariadb.com/docs/server/server-management/variables-and-modes/server-system-variables#old_passwords) is set, and create a user account via [CREATE USER](https://mariadb.com/docs/server/sql-statements/account-management-sql-statements/create-user#identified-by-password) that does not specify an authentication plugin, but instead specifies a password via the [IDENTIFIED BY](https://github.com/mariadb-corporation/mariadb-docs/blob/main/server/reference/sql-statements-and-structure/sql-statements/account-management-sql-commands/create-user.md#identified-by-password) clause:

```sql
SET old_passwords=1;
CREATE USER username@hostname IDENTIFIED BY 'mariadb';
```

If [SQL\_MODE](https://mariadb.com/docs/server/server-management/variables-and-modes/sql_mode) does not have `NO_AUTO_CREATE_USER` set, then you can also create the user via [GRANT](https://mariadb.com/docs/server/reference/sql-statements/account-management-sql-statements/grant):

```sql
SET old_passwords=1;
GRANT SELECT ON db.* TO username@hostname IDENTIFIED BY 'mariadb';
```

You can also create the user account by providing a password hash via the [IDENTIFIED BY PASSWORD](https://mariadb.com/docs/server/sql-statements/account-management-sql-statements/create-user#identified-by-password) clause, and MariaDB validates whether the password hash is one that is compatible with `mysql_old_password`:

```sql
SET old_passwords=1;
Query OK, 0 rows affected (0.000 sec)

SELECT PASSWORD('mariadb');
+---------------------+
| PASSWORD('mariadb') |
+---------------------+
| 021bec665bf663f1    |
+---------------------+
1 row in set (0.000 sec)

CREATE USER username@hostname IDENTIFIED BY PASSWORD '021bec665bf663f1';
Query OK, 0 rows affected (0.000 sec)
```

Similar to all other [authentication plugins](https://mariadb.com/docs/server/reference/plugins/authentication-plugins), you could also specify the name of the plugin in the `IDENTIFIED VIA` clause, while providing the password hash as the `USING` clause:

```sql
CREATE USER username@hostname IDENTIFIED VIA mysql_old_password USING '021bec665bf663f1';
Query OK, 0 rows affected (0.000 sec)
```

## Changing User Passwords

You can change a user account's password with the [SET PASSWORD](https://mariadb.com/docs/server/reference/sql-statements/account-management-sql-statements/set-password) statement, while providing the plain-text password as an argument to the [PASSWORD()](https://mariadb.com/docs/server/reference/sql-functions/secondary-functions/encryption-hashing-and-compression-functions/password) function:

```sql
SET PASSWORD =  PASSWORD('new_secret')
```

You can also change the user account's password with the [ALTER USER](https://mariadb.com/docs/server/reference/sql-statements/account-management-sql-statements/alter-user) statement. You have to make sure that [old\_passwords=1](https://github.com/mariadb-corporation/mariadb-docs/blob/main/server/server-usage/replication-cluster-multi-master/optimization-and-tuning/system-variables/server-system-variables.md#old_passwords) is set, and you have to specify a password via the [IDENTIFIED BY](https://mariadb.com/docs/server/sql-statements/account-management-sql-statements/create-user#identified-by-password) clause:

```sql
SET old_passwords=1;
ALTER USER username@hostname IDENTIFIED BY 'new_secret';
```

## Client Authentication Plugins

For clients that use the `libmysqlclient` or [MariaDB Connector/C](https://app.gitbook.com/s/CjGYMsT2MVP4nd3IyW2L/mariadb-connector-c) libraries, MariaDB provides one client authentication plugin that is compatible with the `mysql_old_password` authentication plugin:

* `mysql_old_password`

When connecting with a [client or utility](https://mariadb.com/docs/server/clients-and-utilities) to a server as a user account that authenticates with the `mysql_old_password` authentication plugin. You may need to tell the client where to find the relevant client authentication plugin by specifying the `--plugin-dir` option:

```bash
mysql --plugin-dir=/usr/local/mysql/lib64/mysql/plugin --user=alice
```

However, the `mysql_old_password` client authentication plugin is generally statically linked into client libraries like `libmysqlclient` or [MariaDB Connector/C](https://app.gitbook.com/s/CjGYMsT2MVP4nd3IyW2L/mariadb-connector-c), so this is not usually necessary.

### `mysql_old_password`

The `mysql_old_password` client authentication plugin hashes the password before sending it to the server.

## Support in Client Libraries

The `mysql_old_password` authentication plugin is one of the conventional authentication plugins, so all client libraries should support it.

<sub>*This page is licensed: CC BY-SA / Gnu FDL*</sub>

{% @marketo/form formId="4316" %}


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://mariadb.com/docs/server/reference/plugins/authentication-plugins/authentication-plugin-mysql_old_password.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
