# SASL/LDAP Authentication: Error: Couldn't find mech PLAIN

**URL:** <https://forums.percona.com/t/sasl-ldap-authentication-error-couldnt-find-mech-plain/33026>\
**Category:** Percona Server for MongoDB\
**Tags:** percona, mongodb\
**Created:** [September 10, 2024, 6:26am UTC](https://forums.percona.com/t/sasl-ldap-authentication-error-couldnt-find-mech-plain/33026 "2024-09-10T06:26:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![litchan](https://avatars.discourse-cdn.com/v4/letter/l/8dc957/32.png) [@litchan](https://forums.percona.com/u/litchan)\
**Post date:** [September 10, 2024, 6:26am UTC](https://forums.percona.com/t/sasl-ldap-authentication-error-couldnt-find-mech-plain/33026/1 "2024-09-10T06:26:40Z")

</div>

hello,  
We was start a percona server for mongodb Instance with docker image ‘percona/percona-server-mongodb:5.0’. The LDAP authentication with SASL was work on it. But the LDAP authentication does not work when we upgrade the percona server for mongodb to 6.0 by change image to ‘percona/percona-server-mongodb:6.0.16’.  
The saslauthd service is work, because testsaslauthd command return `0:OK "Success"` .  
The libsasl2 configuration file was named /etc/sasl2/mongodb.conf and content is  
pwcheck\_method: saslauthd  
saslauthd\_path: /var/run/saslauthd/mux  
log\_level: 5  
mech\_list: plain

error log:  
{“t”:{“$date”:“2024-09-01T05:33:58.031+00:00”},“s”:“I”, “c”:“ACCESS”, “id”:29052, “ctx”:“conn15”,“msg”:“SASL server message: ({priority}) {msg}”,“attr”:{“priority”:2,“msg”:“Couldn’t find mech PLAIN”}}  
{“t”:{“$date”:“2024-09-01T05:33:58.031+00:00”},“s”:“I”, “c”:“ACCESS”, “id”:20249, “ctx”:“conn15”,“msg”:“Authentication failed”,“attr”:{“mechanism”:“PLAIN”,“speculative”:false,“principalName”:“”,“authenticationDatabase”:“$external”,“remote”:“xxx.xxx.xx.xxx:yyyy”,“extraInfo”:{},“error”:“OperationFailed: SASL step did not complete: (no mechanism available)”}}

---

<div class="post-metadata">

**Author:** ![radoslaw.szulgo](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/radoslaw.szulgo/32/17315_2.png) [@radoslaw.szulgo](https://forums.percona.com/u/radoslaw.szulgo)\
**Post date:** [September 10, 2024, 7:54am UTC](https://forums.percona.com/t/sasl-ldap-authentication-error-couldnt-find-mech-plain/33026/2 "2024-09-10T07:54:56Z")

</div>

Hi,  
I recommend that you reconfigure your MongoDB cluster with native LDAP rather than SASL proxy if possible. Here you have some more information:

> **[Percona Server for MongoDB 7.0 - LDAP authorization](https://docs.percona.com/percona-server-for-mongodb/7.0/authorization.html)**
>
> LDAP authorization allows you to control user access and operations in your database environment using the centralized user management storage – an LDAP server. You create and manage user credentials and permission information in the LDAP server. In...

---

<div class="post-metadata">

**Author:** ![jaimes](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/jaimes/32/20419_2.png) [@jaimes](https://forums.percona.com/u/jaimes)\
**Post date:** [June 18, 2025, 1:58pm UTC](https://forums.percona.com/t/sasl-ldap-authentication-error-couldnt-find-mech-plain/33026/3 "2025-06-18T13:58:47Z")

</div>

Hi,  
The package cyrus-sasl-plain is not included in the docker images for PSMDB 6.0, 7.0 and 8.0 which is why you cannot authenticate with plain SASL authentication. I’ve created a bug report on this here: [Jira](https://perconadev.atlassian.net/browse/PSMDB-1730)

The workaround would be to install that package or better yet use Native LDAP authentication as recommended by Radoslaw. Let us know if you face issues with setting up native LDAP authentication.
