Menu

MySQL Error 1043: Bad Handshake

Troubleshoot MySQL Error 1043 by checking classic port 3306 vs X Protocol 33060, server handshake counters, proxies, and TLS evidence.

Posted on By
On this page

MySQL Error 1043 (08S01, ER_HANDSHAKE_ERROR) means the server rejected a connection handshake as invalid. The message is simply Bad handshake; it does not identify one specific cause. See the MySQL 8.4 error reference.

Confirm the client is using the intended MySQL protocol and port

Check the exact endpoint configured in the application and verify which MySQL protocol its driver uses. The classic MySQL protocol uses the server’s port setting (3306 by default). MySQL X Protocol uses the separate mysqlx_port setting (33060 by default). A client or proxy speaking one protocol to a port configured for the other can fail before account authentication. See the MySQL port reference.

If an administrator can connect to the server, confirm the configured values:

SHOW GLOBAL VARIABLES WHERE Variable_name IN ('port', 'mysqlx_port');

Use a driver and protocol that match the endpoint; do not change the password or grants to fix a handshake error. For a basic TCP reachability failure that happens before MySQL replies, see Error 2003: can’t connect to the MySQL server.

Check handshake counters and the server log

For a remote TCP client, an administrator can inspect the relevant host-cache counters:

SELECT
  IP,
  HOST,
  HOST_VALIDATED,
  COUNT_HANDSHAKE_ERRORS,
  COUNT_SSL_ERRORS,
  COUNT_AUTHENTICATION_ERRORS,
  LAST_ERROR_SEEN
FROM performance_schema.host_cache
WHERE IP = '203.0.113.25';

Replace the example address with the client IP as seen by the server. COUNT_HANDSHAKE_ERRORS records wire-protocol handshake errors, while COUNT_SSL_ERRORS and COUNT_AUTHENTICATION_ERRORS track different categories. These are diagnostic counters, not a one-to-one mapping to Error 1043. For the exact meanings and other counters, see the host_cache table reference. Correlate them with the MySQL error log and the client or proxy logs at the same time.

If traffic passes through a load balancer, proxy, or tunnel, confirm that it forwards the configured MySQL protocol to the intended server and port. A proxy endpoint can be reachable over TCP while still forwarding the wrong service or altering a connection exchange.

Review TLS only when the evidence points to it

Error 1043 alone does not prove a TLS configuration problem. If the client or server log reports a TLS negotiation failure, compare the TLS protocols and ciphers permitted by both sides. MySQL 8.4 supports TLS 1.2 and TLS 1.3, and a successful TLS connection requires the client and server to share a permitted protocol and compatible cipher. See MySQL 8.4 TLS protocols and ciphers.

Do not disable TLS as a blanket workaround. If a test without TLS changes the result, use that only to identify the failing layer, then restore encryption and correct the TLS configuration.

  • Error 1043: the server reports a bad handshake; check protocol, port, proxy, and relevant server counters.
  • Error 1042: the server cannot get the hostname for the client address; see Error 1042 troubleshooting.
  • Error 1045: the server rejects account authentication; see Error 1045 troubleshooting.
  • Error 1129: the server blocks a host after repeated connection errors; see Error 1129 troubleshooting.

Use the MySQL connection error triage helper to route common connection codes, or browse MySQL Error Troubleshooting.