Accounts and Auth Plugins

Accounts, Hosts, and Authentication Plugins

An account is a user name plus a host: 'shop_app'@'localhost' and 'shop_app'@'%' are two accounts with separate passwords and privileges. The host is localhost (the Unix socket), an address, a pattern such as '10.0.0.%' or '10.0.0.0/24', or '%' for anywhere, the default. When several accounts match, the most specific host wins. Each account also names the authentication plugin that checks its credentials:

The login accounts of a fresh server, and a plugin that is goneSQL
SELECT user, host, plugin, LEFT(authentication_string, 7) AS hash
FROM mysql.user WHERE user NOT LIKE 'mysql.%';
CREATE USER 'legacy'@'%' IDENTIFIED WITH mysql_native_password BY 'Legacy#Pass-2026';
Output
+------+-----------+-----------------------+---------+
| user | host      | plugin                | hash    |
+------+-----------+-----------------------+---------+
| root | %         | caching_sha2_password | $A$00A$ |
| root | localhost | caching_sha2_password | $A$00A$ |
+------+-----------+-----------------------+---------+
ERROR 1524 (HY000) at line 3: Plugin 'mysql_native_password' is not loaded

$A$00A$ is the caching_sha2_password format, the only default, with 10,000 (hex 00A thousand) rounds of salted SHA-256. mysql_native_password stored an unsalted double SHA-1; it was deprecated in 8.0.34, disabled in 8.4 and removed in 9.0, hence error 1524, so switch old accounts with ALTER USER ... IDENTIFIED WITH caching_sha2_password before upgrading. Ubuntu 225 's root uses auth_socket (Installing MySQL on Ubuntu); sha256_password is deprecated; LDAP, Kerberos and WebAuthn logins are Enterprise Edition only.