Menu

MySQL Error 2059: Authentication Plugin Cannot Be Loaded

Troubleshoot client-side MySQL Error 2059 by checking connector support, loaded client libraries, plugin directories, and authentication compatibility.

Posted on By
On this page

MySQL Error 2059 (CR_AUTH_PLUGIN_CANNOT_LOAD) is raised by the client library when it cannot load the authentication plugin named in the message. SQLSTATE HY000 is generic for client errors; the plugin name and operating-system loader detail after the colon are more useful for diagnosis. See Oracle’s MySQL 8.4 client error reference.

For example, an error may look like this:

ERROR 2059 (HY000): Authentication plugin 'caching_sha2_password' cannot be loaded: ...

This does not by itself mean the server is missing that plugin. It means the client process failed to load or use its client-side implementation.

Identify which client and plugin are failing

Record the complete error, including the plugin name and text after the colon. Then identify the client that actually opens the connection: the mysql command-line client, an application connector, a driver bundled by a runtime, or a library linked into the application. Updating a separate mysql executable does not update a connector bundled inside a running application.

If an administrator can query the server, check the plugin configured for the matching account:

SELECT User, Host, plugin
FROM mysql.user
WHERE User = 'app_user';

Replace app_user with the account name and verify the matching host row. Querying mysql.user requires administrative access; do not publish account lists or other sensitive output.

Update the client library or connector

If the message names caching_sha2_password, the client or connector may be too old to support that authentication method, or it may be loading an older client library at runtime. Install a connector version that supports the server account’s authentication plugin, then restart the application so it loads the updated library. MySQL 8.4’s caching_sha2_password implementation is built into the current libmysqlclient library; see the official Caching SHA-2 authentication documentation.

For language drivers that implement the MySQL protocol themselves, check the driver version and its own authentication-plugin support. Replacing the system libmysqlclient will not help a driver that does not use it.

Check the client plugin directory when the plugin is external

Some client authentication plugins are separate library files. If the message says a specific plugin file cannot be found or loaded, confirm that the intended client plugin is installed for the same operating system, architecture, and client-library ABI as the application. For the standard mysql client, --plugin-dir sets the directory where client plugins are searched. The C client library also supports the LIBMYSQL_PLUGIN_DIR environment variable. See the MySQL client options and client plugin interface.

Do not copy an arbitrary plugin library into a plugin directory. Use a library supplied for the exact client distribution and verify its source. If the plugin is built into the client library, changing a plugin directory cannot add support to an old library; update the client instead.

Distinguish Error 2059 from server-side Error 1524

These errors describe different failures:

  • Error 2059: the client library cannot load the named client-side authentication plugin. Check the client, its linked libraries, and any external plugin directory.
  • Error 1524: the server reports that a requested server-side plugin is not loaded, often when creating or altering an account with mysql_native_password on MySQL 8.4. See MySQL Error 1524 troubleshooting.
  • Error 1045: the server rejected authentication for the account. Check the password, matching user@host, account plugin, and client support; see MySQL Error 1045 troubleshooting.

MySQL 8.4 disables server-side mysql_native_password by default, and MySQL 9.0 removes it. If Error 2059 names that plugin, do not assume enabling the server-side plugin will fix a missing client-side implementation. Prefer updating the client and migrating accounts to caching_sha2_password; for upgrade planning, see how to upgrade MySQL 8.0 to 8.4 LTS.