# Does pt-online-schema-change tool support IAM based user authentications?

**URL:** <https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244>\
**Category:** Other Tools\
**Created:** [November 6, 2020, 1:38pm UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244 "2020-11-06T13:38:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dinesh082293](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/dinesh082293/32/10176_2.png) [@dinesh082293](https://forums.percona.com/u/dinesh082293)\
**Post date:** [November 6, 2020, 1:38pm UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244/1 "2020-11-06T13:38:46Z")

</div>

Facing issues when using IAM token based authentication with percona tools like pt-online-schema-change. pt-online-schema-change tool might be truncating or tweaking the password value on the command execution and this may be failing authentication.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [November 9, 2020, 2:25pm UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244/2 "2020-11-09T14:25:39Z")

</div>

@dinesh082293 Can you please provide an example of how you are executing pt-osc with IAM? I’m not aware of any native IAM integration so I’m curious as to what exactly you are doing.

---

<div class="post-metadata">

**Author:** ![dinesh082293](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/dinesh082293/32/10176_2.png) [@dinesh082293](https://forums.percona.com/u/dinesh082293)\
**Post date:** [November 17, 2020, 1:46am UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244/3 "2020-11-17T01:46:19Z")

</div>

@matthewb When i generate IAM token and use that password with below command, it fails with access denied error.

Command used:

pt-online-schema-change D=XXXX,t=XXXX,u=XXXX,[h=XXXX.rds.amazonaws.com](http://h=XXXX.rds.amazonaws.com) --ask-pass --critical-load Threads\_running=1500 --alter-foreign-keys-method auto --recursion-method none --progress percentage,1 --no-check-alter --nodrop-old-table --execute --alter "ADD INDEX “XXXXX;”

Used the same token to login into the RDS via MySQL client through IAM authentication and it was successful. And i was able to use pt-online-schema-change as normal user. Issue[access denied] only comes when i use pt-online-schema-change with IAM token.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [November 17, 2020, 9:46am UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244/4 "2020-11-17T09:46:13Z")

</div>

@dinesh082293 , I’m unfamiliar with IAM tokens so I cannot comment on that. All I know is that there is no direct native IAM integration with any percona-toolkit tools. Can you tell me which mysql client you are using? Community? MariaDB? Run this command please “sudo rpm -qa | grep -i mysql” and then run again for “grep -i percona” Thanks.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [November 17, 2020, 9:47am UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244/5 "2020-11-17T09:47:57Z")

</div>

@dinesh082293 Are these the steps that you followed?

[https://aws.amazon.com/premiumsupport/knowledge-center/users-connect-rds-iam/](https://aws.amazon.com/premiumsupport/knowledge-center/users-connect-rds-iam/)

---

<div class="post-metadata">

**Author:** ![dinesh082293](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/dinesh082293/32/10176_2.png) [@dinesh082293](https://forums.percona.com/u/dinesh082293)\
**Post date:** [November 17, 2020, 11:32pm UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244/6 "2020-11-17T23:32:01Z")

</div>

@matthewb Thanks for the response.

Yes these are the steps we follow and we are using Amazon aurora mysql.

---

<div class="post-metadata">

**Author:** ![David\_Santucci](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/david_santucci/32/6309_2.png) [@David\_Santucci](https://forums.percona.com/u/David_Santucci)\
**Post date:** [April 13, 2022, 7:03pm UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244/7 "2022-04-13T19:03:17Z")

</div>

I was able to get pt-online-schema-change to connect using an IAM access token by setting the LIBMYSQL\_ENABLE\_CLEARTEXT\_PLUGIN environment variable to 1 and adding “mysql\_ssl=1” to the DBI connection string, similar to [this script](https://github.com/pplu/perl-rds-iam-authentication/blob/master/rds_iam_connect.pl).

pt-online-schema-change doesn’t seem to provide any way of setting the DBI “mysql\_ssl” flag. Could that be added to the options somehow?

---

<div class="post-metadata">

**Author:** ![David\_Santucci](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/david_santucci/32/6309_2.png) [@David\_Santucci](https://forums.percona.com/u/David_Santucci)\
**Post date:** [April 14, 2022, 7:52pm UTC](https://forums.percona.com/t/does-pt-online-schema-change-tool-support-iam-based-user-authentications/8244/8 "2022-04-14T19:52:08Z")

</div>

UPDATE: You can just tack “;mysql\_ssl=1” onto the host portion of the DSN, and it works:

```auto
export LIBMYSQL_ENABLE_CLEARTEXT_PLUGIN=1
port=3306
region="us-east-1"
host="your-rds-instance.us-east-1.rds.amazonaws.com"
user="your_iam_username"
token=$(aws rds generate-db-auth-token --hostname $host --port $port --username $user --region $region)

pt-online-schema-change --dry-run --alter "CHANGE COLUMN id id BIGINT UNSIGNED NOT NULL auto_increment" "D=your_database,t=your_table,h=$host;mysql_ssl=1,u=$user,p=$token"

```

Is this officially supported functionality, or could this be broken by an update to the DSN parser?
