Skip to content

Troubleshoot database connection errors

If you encounter database connection errors during a cPFence database scan, this guide will help you resolve them. A failed connection is not a clean scan result.

cPFence v4+ uses its native database scanner. Read the failed site’s output and check /var/log/cpfenceav/wordpress_db_scan_error.log on its server.

A possible cause is skip-name-resolve in the MySQL or MariaDB configuration together with database-user grants that depend on a hostname. A socket connection and a TCP connection may match different grants. Check the actual database host and connection before changing settings.

Check the affected site’s connection first

Section titled “Check the affected site’s connection first”
  1. Check whether the WordPress site itself can access its database.
  2. Review its database host, port or socket and database-user grants with the site/database administrator. Keep credentials out of shared logs.
  3. Check the connection in the site’s actual user/container environment. A successful host-shell connection does not prove the site’s connection works.

Change database settings when name resolution is the cause

Section titled “Change database settings when name resolution is the cause”

If the database administrator confirms that skip-name-resolve conflicts with the intended grants, the original server-wide solution is:

  1. Save a copy of the active MySQL configuration file, for example /etc/mysql/conf.d/enhance.cnf. Check the actual file used by this server.

  2. Remove or comment out this line, if present:

    skip-name-resolve
  3. Save the file. During an agreed maintenance window, restart the database service on the affected server:

    Terminal window
    sudo systemctl restart mysql
  4. Check that MySQL is running and the affected sites can connect. If the change fails, restore the saved configuration and resolve the service error before continuing.

Once the connection is working, rerun only the affected site’s database scan in the WebUI and inspect the final result.

Contact support through your client portal, with the failure time and relevant redacted error lines.