Java+Tomcat连接MySQL8报错:无法加载auth_gssapi_client认证插件
auth_gssapi_client加载错误 问题重现
在基于Java+Apache Tomcat搭建的应用中,连接MySQL 8数据库时触发如下错误:
com.mysql.cj.exceptions.WrongArgumentException: Unable to load authentication plugin 'auth_gssapi_client'
本地环境运行正常,但部署到线上服务器后出现该问题,完整报错栈:
19-Feb-2024 14:23:09.678 SEVERE [http-nio-8080-exec-8] org.apache.catalina.core.StandardWrapperValve.invoke Servlet.service() for servlet [dms] in context with path [] threw exception [Request processing failed; nested exception is org.springframework.transaction.CannotCreateTransactionException: Could not open Hibernate Session for transaction; nested exception is org.hibernate.exception.JDBCConnectionException: Could not open connection] with root cause
com.mysql.cj.exceptions.WrongArgumentException: Unable to load authentication plugin 'auth_gssapi_client'.
解决方案
1. 调整JDBC连接URL参数
直接在连接URL中指定认证插件或禁用插件切换,强制使用兼容的认证方式:
- 方式一:指定使用
mysql_native_password插件jdbc:mysql://your-db-host:3306/your-db-name?useSSL=false&serverTimezone=UTC&authenticationPlugin=mysql_native_password - 方式二:禁用认证插件自动切换
jdbc:mysql://your-db-host:3306/your-db-name?useSSL=false&serverTimezone=UTC&disableAuthPluginSwitch=true
2. 修正线上MySQL用户的认证插件
登录线上MySQL服务器,检查目标数据库用户的认证插件配置:
SELECT user, host, plugin FROM mysql.user WHERE user='your-db-username';
如果查询结果中plugin字段为auth_gssapi_client,将其改为mysql_native_password:
ALTER USER 'your-db-username'@'%' IDENTIFIED WITH mysql_native_password BY 'your-db-password'; FLUSH PRIVILEGES;
3. 统一MySQL Connector/J版本
确保线上Tomcat环境使用的mysql-connector-java.jar版本与本地一致,且为适配MySQL 8的8.0.x系列版本。旧版5.x驱动对MySQL 8的新认证插件支持不完善,容易引发此类错误。
4. 排除线上环境依赖问题
若上述方法无效,可排查线上服务器是否缺失GSSAPI相关依赖,但不建议补全该依赖(因为业务不需要此认证方式),优先通过前面的方法禁用该插件加载。
内容的提问来源于stack exchange,提问作者Preeti

