# Password expired for all user accounts

**URL:** <https://forums.percona.com/t/password-expired-for-all-user-accounts/5396>\
**Category:** Percona Server for MySQL 5.7\
**Created:** [February 4, 2017, 8:37pm UTC](https://forums.percona.com/t/password-expired-for-all-user-accounts/5396 "2017-02-04T20:37:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rein\_vtv](https://avatars.discourse-cdn.com/v4/letter/r/54ee81/32.png) [@Rein\_vtv](https://forums.percona.com/u/Rein_vtv)\
**Post date:** [February 4, 2017, 8:37pm UTC](https://forums.percona.com/t/password-expired-for-all-user-accounts/5396/1 "2017-02-04T20:37:04Z")

</div>

Hey guys, i’ve just done an upgrade from (percona) 5.6 to 5.7 and ran into troubles. Not regarding the upgrade, but regarding password policy of mysql 5.7 :-(.

All accounts on my test server have been marked as expired (about 50 accounts) and therefor websites are unable to use the database server. Does anyone know how I can upgrade without having all accounts expired? Funny enough none of the usernames have a Y at the password\_expired field in mysql.user …

Any insights on the matter are greatly appreciated

---

<div class="post-metadata">

**Author:** ![jrivera](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/jrivera/32/13_2.png) [@jrivera](https://forums.percona.com/u/jrivera)\
**Post date:** [February 5, 2017, 1:32am UTC](https://forums.percona.com/t/password-expired-for-all-user-accounts/5396/2 "2017-02-05T01:32:25Z")

</div>

Did you upgrade from 5.6 to any version between 5.7.4 to 5.7.10? Based on the manual:

> [@](#):
>
> From MySQL 5.7.4 to 5.7.10, the default [default\_password\_lifetime](https://dev.mysql.com/doc/refman/5.7/en/server-system-variables.html#sysvar_default_password_lifetime) value is 360 (passwords must be changed approximately once per year). For those versions, be aware that, if you make no changes to the[default\_password\_lifetime](https://dev.mysql.com/doc/refman/5.7/en/server-system-variables.html#sysvar_default_password_lifetime) variable or to individual user accounts, all user passwords will expire after 360 days, and all user accounts will start running in restricted mode when this happens. Clients (which are effectively users) connecting to the server will then get an error indicating that the password must be changed: ERROR 1820 (HY000): You must reset your password using ALTER USER statement before executing this statement.
> 
> However, this is easy to miss for clients that automatically connect to the server, such as connections made from scripts. To avoid having such clients suddenly stop working due to a password expiring, make sure to change the password expiration settings for those clients, like this:  
> ALTER USER ‘script’@‘localhost’ PASSWORD EXPIRE NEVER  
> Alternatively, set the [default\_password\_lifetime](https://dev.mysql.com/doc/refman/5.7/en/server-system-variables.html#sysvar_default_password_lifetime) variable to 0, thus disabling automatic password expiration for all users.

---

<div class="post-metadata">

**Author:** ![Rein\_vtv](https://avatars.discourse-cdn.com/v4/letter/r/54ee81/32.png) [@Rein\_vtv](https://forums.percona.com/u/Rein_vtv)\
**Post date:** [February 5, 2017, 2:44am UTC](https://forums.percona.com/t/password-expired-for-all-user-accounts/5396/3 "2017-02-05T02:44:16Z")

</div>

Well, that’s just it. I’ve ran into this problem when testing some months ago, and reverted back to 5.6. Now I went from 5.6 to the latest 5.7.17-11 and expected not to run into it. I did run mysql\_upgrade afterwards, but I don’t think that’s a bad thing?

---

<div class="post-metadata">

**Author:** ![jrivera](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/jrivera/32/13_2.png) [@jrivera](https://forums.percona.com/u/jrivera)\
**Post date:** [February 5, 2017, 3:01am UTC](https://forums.percona.com/t/password-expired-for-all-user-accounts/5396/4 "2017-02-05T03:01:40Z")

</div>

Upgrading major versions like in your case from 5.6 to 5.7, running mysql\_upgrade is recommended if not required 🙂

Just make sure to check all variables pertaining to password expiry to NOT expire 🙂

---

<div class="post-metadata">

**Author:** ![Rein\_vtv](https://avatars.discourse-cdn.com/v4/letter/r/54ee81/32.png) [@Rein\_vtv](https://forums.percona.com/u/Rein_vtv)\
**Post date:** [February 5, 2017, 3:50am UTC](https://forums.percona.com/t/password-expired-for-all-user-accounts/5396/5 "2017-02-05T03:50:50Z")

</div>

SHOW VARIABLES LIKE “default\_pass%”;  
±--------------------------±------+  
| Variable\_name | Value |  
±--------------------------±------+  
| default\_password\_lifetime | 0 |  
±--------------------------±------+  
1 row in set (0.00 sec)

but it passwords are still marked as expired.  
Is there a query I can run to unexpire them?

---

<div class="post-metadata">

**Author:** ![jrivera](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/jrivera/32/13_2.png) [@jrivera](https://forums.percona.com/u/jrivera)\
**Post date:** [February 5, 2017, 3:57am UTC](https://forums.percona.com/t/password-expired-for-all-user-accounts/5396/6 "2017-02-05T03:57:18Z")

</div>

Run ALTER USER ‘username’ PASSWORD EXPIRE NEVER
