MySQL 8: Public Key Retrieval is not allowed
- Platforms
- Paper · Purpur · Velocity · single server
- Verified
- Verified
- Confidence
- Confidence 95%
What it looks like in the log
Any one of these lines is enough. The agent matches them locally, on your server.
logs/latest.log
[WARN] Public Key Retrieval is not allowed
Symptoms
- A plugin cannot connect to MySQL 8: “Public Key Retrieval is not allowed”
Cause
The MySQL 8 user uses caching_sha2_password, the connection is made without SSL, and the driver is not allowed to request the server's public RSA key (allowPublicKeyRetrieval=false).
Possible causes
- The plugin's JDBC parameters lack allowPublicKeyRetrieval=true while useSSL=false
- The database user was switched to caching_sha2_password (the MySQL 8 default) after a MySQL upgrade
How to fixLow risk
- Preferred: enable SSL for the connection (
useSSL=true, andrequireSSL=trueif needed) — then the key is not needed. - Alternatively, add
allowPublicKeyRetrieval=trueto the plugin's JDBC parameters (for LuckPerms — indata.pool-settings.properties); only do this on a trusted network between the server and the database. - Another option: switch the user to
mysql_native_password(a legacy method; disabled by default in MySQL 8.4+). - Restart the server or reload the plugin.
Translated from the Russian original; log lines are quoted verbatim.