# ERROR 1045 (28000): Access denied for user ‘mysql.pxc.sst.user’@

**URL:** <https://forums.percona.com/t/error-1045-28000-access-denied-for-user-mysql-pxc-sst-user/21484>\
**Category:** Percona XtraDB Cluster 8.x\
**Tags:** percona\
**Created:** [April 18, 2023, 6:16pm UTC](https://forums.percona.com/t/error-1045-28000-access-denied-for-user-mysql-pxc-sst-user/21484 "2023-04-18T18:16:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chanakya](https://avatars.discourse-cdn.com/v4/letter/c/cab0a1/32.png) [@Chanakya](https://forums.percona.com/u/Chanakya)\
**Post date:** [April 18, 2023, 6:16pm UTC](https://forums.percona.com/t/error-1045-28000-access-denied-for-user-mysql-pxc-sst-user/21484/1 "2023-04-18T18:16:41Z")

</div>

Hi,

Cluster is not coming up with below error:

Receiver:  
2023-04-18T18:05:06.031607Z 0 [Warning] [MY-000000] [Galera] 0.0 (XXXXX): State transfer to 1.0 (XXXXXX) failed: -1 (Operation not permitted)

2023-04-18T18:05:06.031665Z 0 [ERROR] [MY-000000] [Galera] gcs/src/gcs\_group.cpp:gcs\_group\_handle\_join\_msg():1216: Will never receive state. Need to abort.

2023-04-18T18:05:06.031679Z 0 [Note] [MY-000000] [Galera] gcomm: terminating thread

2023-04-18T18:05:06.031716Z 0 [Note] [MY-000000] [Galera] gcomm: joining thread

2023-04-18T18:05:06.031862Z 0 [Note] [MY-000000] [Galera] gcomm: closing backend

2023-04-18T18:05:06.531151Z 0 [Note] [MY-000000] [Galera] (94b7573e-bb47, ‘ssl://0.0.0.0:3304’) turning message relay requesting off

2023-04-18T18:05:07.035288Z 0 [Note] [MY-000000] [Galera] Current view of cluster as seen by this node

view (view\_id(NON\_PRIM,5c1c7395-85e4,25)

memb {

94b7573e-bb47,0

}

joined {

}

left {

}

partitioned {

5c1c7395-85e4,0

}

)

2023-04-18T18:05:07.035354Z 0 [Note] [MY-000000] [Galera] PC protocol downgrade 1 → 0

2023-04-18T18:05:07.035365Z 0 [Note] [MY-000000] [Galera] Current view of cluster as seen by this node

view ((empty))

2023-04-18T18:05:07.035545Z 0 [Note] [MY-000000] [Galera] gcomm: closed

2023-04-18T18:05:07.035573Z 0 [Note] [MY-000000] [Galera] /path/to/binaries//bin/mysqld: Terminated.

2023-04-18T18:05:07.035582Z 0 [Note] [MY-000000] [WSREP] Initiating SST cancellation

2023-04-18T18:05:07.035587Z 0 [Note] [MY-000000] [WSREP] Terminating SST process

2023-04-18T18:05:07.037556Z 0 [ERROR] [MY-000000] [WSREP-SST] Removing /path/to/datadir//xtrabackup\_galera\_info file due to signal

Donor:  
2023-04-18T18:05:05.190518Z 2 [Note] [MY-000000] [WSREP] Server status change synced → donor

2023-04-18T18:05:05.190532Z 2 [Note] [MY-000000] [WSREP] wsrep\_notify\_cmd is not defined, skipping notification.

2023-04-18T18:05:05.191224Z 0 [Note] [MY-000000] [WSREP] Initiating SST/IST transfer on DONOR side (wsrep\_sst\_xtrabackup-v2 --role ‘donor’ --address ‘X.X.X.X:3303/xtrabackup\_sst//1’ --socket ‘xxxxx.sock’ --datadir ‘/path/to/datadir/’ --basedir ‘/path/to/binaries/’ --plugindir ‘/path/to/binaries/lib/plugin/’ --defaults-file ‘/path/to/mycnf/my.cnf’ --defaults-group-suffix ‘’ --mysqld-version ‘8.0.31-23.2’ --binlog ‘mysqltest1t\_b\_binlog’ --gtid ‘45e1d077-dd70-11ed-a50b-73de40d8bbd9:89’ --bypass)

2023-04-18T18:05:05.226554Z 2 [Note] [MY-000000] [WSREP] DONOR thread signaled with 0

2023-04-18T18:05:05.279973Z 0 [Note] [MY-000000] [Galera] async IST sender starting to serve ssl://X.X.X.X:3305 sending 90-92, preload starts from 92

2023-04-18T18:05:05.281030Z 0 [Note] [MY-000000] [Galera] IST sender 90 → 92

2023-04-18T18:05:05.999415Z 23 [Warning] [MY-013360] [Server] Plugin sha256\_password reported: ‘‘sha256\_password’ is deprecated and will be removed in a future release. Please use caching\_sha2\_password instead’

2023-04-18T18:05:06.000588Z 0 [Note] [MY-000000] [WSREP-SST] ERROR 1045 (28000): Access denied for user ‘mysql.pxc.sst.user’@‘[vm-17-182-5-155.us-east-1.compute.is.apple.com](http://vm-17-182-5-155.us-east-1.compute.is.apple.com)’ (using password: YES)

2023-04-18T18:05:06.002379Z 0 [ERROR] [MY-000000] [WSREP-SST] Cleanup after exit with status:1

2023-04-18T18:05:06.022374Z 0 [ERROR] [MY-000000] [WSREP] Process completed with error: wsrep\_sst\_xtrabackup-v2 --role ‘donor’ --address ‘X.X.X.X:3303/xtrabackup\_sst//1’ --socket ‘/tmp/mysqld\_mysqltest1t.sock’ --datadir ‘/path/to/datadir/’ --basedir ‘/path/to/binaries/’ --plugindir ‘/path/to/binaries/lib/plugin/’ --defaults-file ‘/path/to/mycnf/my.cnf’ --defaults-group-suffix ‘’ --mysqld-version ‘8.0.31-23.2’ --binlog ‘mysqltest1t\_b\_binlog’ --gtid ‘45e1d077-dd70-11ed-a50b-73de40d8bbd9:89’ --bypass: 1 (Operation not permitted)

2023-04-18T18:05:06.030423Z 0 [Note] [MY-000000] [Galera] SST sending failed: -1

2023-04-18T18:05:06.030455Z 0 [Note] [MY-000000] [WSREP] Server status change donor → joined

2023-04-18T18:05:06.030469Z 0 [Note] [MY-000000] [WSREP] wsrep\_notify\_cmd is not defined, skipping notification.

2023-04-18T18:05:06.030603Z 0 [ERROR] [MY-000000] [WSREP] Command did not run: wsrep\_sst\_xtrabackup-v2 --role ‘donor’ --address ‘X.X.X.X:3303/xtrabackup\_sst//1’ --socket ‘/tmp/mysqld\_mysqltest1t.sock’ --datadir ‘/path/to/datadir/’ --basedir ‘/path/to/binaries/’ --plugindir ‘/path/to/binaries/lib/plugin/’ --defaults-file ‘/path/to/mycnf/my.cnf’ --defaults-group-suffix ‘’ --mysqld-version ‘8.0.31-23.2’ --binlog ‘mysqltest1t\_b\_binlog’ --gtid ‘45e1d077-dd70-11ed-a50b-73de40d8bbd9:89’ --bypass

2023-04-18T18:05:06.031444Z 0 [Warning] [MY-000000] [Galera] 0.0 (X.X.X.X): State transfer to 1.0 (X.X.X.X) failed: -1 (Operation not permitted)

2023-04-18T18:05:06.031535Z 0 [Note] [MY-000000] [Galera] Shifting DONOR/DESYNCED → JOINED (TO: 92)

ISSUE:  
sst user is getting created over localhost however, while actual ssl, mysql connection is resolving to the hostname instead of localhost as below:  
[Note] [MY-000000] [WSREP-SST] ERROR 1045 (28000): Access denied for user ‘mysql.pxc.sst.user’@‘[goianallbgkqhh89889bniga.us-east-1.compute.is.xxxxx.com](http://goianallbgkqhh89889bniga.us-east-1.compute.is.xxxxx.com)’ (using password: YES)

---

<div class="post-metadata">

**Author:** ![Evgeniy\_Patlan](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/evgeniy_patlan/32/41_2.png) [@Evgeniy\_Patlan](https://forums.percona.com/u/Evgeniy_Patlan)\
**Post date:** [April 19, 2023, 1:16pm UTC](https://forums.percona.com/t/error-1045-28000-access-denied-for-user-mysql-pxc-sst-user/21484/2 "2023-04-19T13:16:05Z")

</div>

> [@Chanakya](#):
>
> sst user is getting created over localhost however, while actual ssl, mysql connection is resolving to the hostname instead of localhost as below:  
> [Note] [MY-000000] [WSREP-SST] ERROR 1045 (28000): Access denied for user ‘mysql.pxc.sst.user’@‘[goianallbgkqhh89889bniga.us-east-1.compute.is.xxxxx.com](http://goianallbgkqhh89889bniga.us-east-1.compute.is.xxxxx.com)’ (using password: YES)

please verify that SSL certificate being used for the connection matches the hostname being used

---

<div class="post-metadata">

**Author:** ![Chanakya](https://avatars.discourse-cdn.com/v4/letter/c/cab0a1/32.png) [@Chanakya](https://forums.percona.com/u/Chanakya)\
**Post date:** [April 19, 2023, 10:12pm UTC](https://forums.percona.com/t/error-1045-28000-access-denied-for-user-mysql-pxc-sst-user/21484/3 "2023-04-19T22:12:24Z")

</div>

I disabled SSL. Regardless sst is supposed to connect using localhost but not hostname. Is there a way to add host option to sst ?

---

<div class="post-metadata">

**Author:** ![yunus\_shaikh](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/yunus_shaikh/32/3512_2.png) [@yunus\_shaikh](https://forums.percona.com/u/yunus_shaikh)\
**Post date:** [April 20, 2023, 1:42am UTC](https://forums.percona.com/t/error-1045-28000-access-denied-for-user-mysql-pxc-sst-user/21484/4 "2023-04-20T01:42:40Z")

</div>

Can you post us the output for

`show global variables where variable_name in ('skip_name_resolve',' pxc-encrypt-cluster-traffic');`
