MariaDB OLD_PASSWORD() Function
Learn what MariaDB OLD_PASSWORD() returns, why it exists for pre-4.1 compatibility, and why it must not be used for new accounts or application passwords.
On this page
MariaDB OLD_PASSWORD(str) calculates the pre-MySQL 4.1 password format. MariaDB retains it only for compatibility with very old clients and accounts. The format is insecure and must not be used for new accounts or application passwords. See MariaDB’s documentation for the mysql_old_password authentication plugin.
Syntax
OLD_PASSWORD(str)
The function returns a 16-character hexadecimal string. This query demonstrates the legacy format:
SELECT OLD_PASSWORD('sample');
Do not store this result in an application user table or use it to protect credentials.
Legacy account compatibility
The mysql_old_password authentication plugin is intended for clients that cannot use newer authentication methods. MariaDB says not to use it for new installations. For current database accounts, use supported account-management statements and authentication plugins; see CREATE USER and MariaDB authentication plugins.
OLD_PASSWORD() is not a modern password-storage function. The MariaDB PASSWORD() function is also limited to MariaDB Server account authentication and is not intended for application passwords. For application logins, use a maintained password-hashing library such as Argon2id, bcrypt, or PBKDF2; see the OWASP Password Storage Cheat Sheet.
Summary
OLD_PASSWORD() exists for legacy account compatibility, not new authentication systems. Avoid it in application code and new MariaDB accounts.