Skip to content
Tickwise
ErrorDatabasesSIG-DB-006

MySQL 8: Public Key Retrieval is not allowed

Platforms
Paper · Purpur · Velocity · single server
Verified
Verified
Confidence
Confidence 95%

What it looks like in the log

Any one of these lines is enough. The agent matches them locally, on your server.

logs/latest.log
  • [WARN] Public Key Retrieval is not allowed

Symptoms

  • A plugin cannot connect to MySQL 8: “Public Key Retrieval is not allowed”

Cause

The MySQL 8 user uses caching_sha2_password, the connection is made without SSL, and the driver is not allowed to request the server's public RSA key (allowPublicKeyRetrieval=false).

Possible causes

  • The plugin's JDBC parameters lack allowPublicKeyRetrieval=true while useSSL=false
  • The database user was switched to caching_sha2_password (the MySQL 8 default) after a MySQL upgrade

How to fixLow risk

  1. Preferred: enable SSL for the connection (useSSL=true, and requireSSL=true if needed) — then the key is not needed.
  2. Alternatively, add allowPublicKeyRetrieval=true to the plugin's JDBC parameters (for LuckPerms — in data.pool-settings.properties); only do this on a trusted network between the server and the database.
  3. Another option: switch the user to mysql_native_password (a legacy method; disabled by default in MySQL 8.4+).
  4. Restart the server or reload the plugin.

Translated from the Russian original; log lines are quoted verbatim.

Sources