# SASL Authentication Error when connect to confluent cloud

**URL:** <https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111>\
**Category:** Confluent Cloud\
**Created:** [17 October 2021 06:21 UTC](https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111 "2021-10-17T06:21:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yanming-li](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/yanming-li/32/1214_2.png) [@yanming-li](https://forum.confluent.io/u/yanming-li)\
**Post date:** [17 October 2021 06:21 UTC](https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111/1 "2021-10-17T06:21:07Z")

</div>

HI,  
I just opened new account, and tried to connect to the cluster(confluent cloud standard). I’m using python 3.6, confluent-kafka 1.7.0 (SASL\_SSL, PLAIN).

I’m getting the following error when I’m trying to connect to my cluster:

%3|1634248587.171|FAIL|schedule-1#producer-1| [thrd:sasl\_ssl://[xxx.us](http://pkc-pgq85.us/)-west-2.aws.confluent.cloud:9092/bootstr]: sasl\_ssl://[xxx.us](http://pkc-pgq85.us/)-west-2.aws.confluent.cloud:9092/bootstrap: SASL authentication error: Authentication failed (after 5104ms in state AUTH\_REQ)

python code:# Kafka  
bootstrap.servers=xxx.us-west-2.aws.confluent.cloud:9092  
security.protocol=SASL\_SSL  
sasl.mechanisms=PLAIN  
sasl.username={{ CLUSTER\_API\_KEY }}  
sasl.password={{ CLUSTER\_API\_SECRET }}

#not using schema registry  
Thanks for your tips

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [18 October 2021 09:46 UTC](https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111/2 "2021-10-18T09:46:29Z")

</div>

Hi,

did you try to telnet the port whether it’s reachable from your env?  
just to be sure that there is no network issue

something like

> telnet xxx.us-west-2.aws.confluent.cloud 9092

---

<div class="post-metadata">

**Author:** ![yanming-li](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/yanming-li/32/1214_2.png) [@yanming-li](https://forum.confluent.io/u/yanming-li)\
**Post date:** [18 October 2021 16:49 UTC](https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111/3 "2021-10-18T16:49:57Z")

</div>

The same bootstrap\_servers had worked earlier using an account with my personal credit card and cluster I created for testing purpose.  
I started to see this error when we closed my old account and created a new account(linked to corporate AWS account) by my coworker. The two clusters, the one from my old account and the one created by my coworker, share the same bootstrap.servers url (us-west-2). I have used the sasl\_user and sasl\_password from the new account though.  
if I run "openssl " against the bootstrap url, I can reach the server and output the certificate.  
Thanks

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [19 October 2021 06:14 UTC](https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111/4 "2021-10-19T06:14:51Z")

</div>

ok I see so it seems not related to network issues

does the cluser version differ?

best,  
Michael

---

<div class="post-metadata">

**Author:** ![yanming-li](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/yanming-li/32/1214_2.png) [@yanming-li](https://forum.confluent.io/u/yanming-li)\
**Post date:** [19 October 2021 16:16 UTC](https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111/5 "2021-10-19T16:16:05Z")

</div>

My old one (worked, personal account) was “basic” subscription, and the current subscription(failing SASL, corporate account) is “standard” subscription. They share the same bootstrap urls(from us-west-2), so I guess the cluster versions should be the same.  
Thanks

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [20 October 2021 11:51 UTC](https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111/6 "2021-10-20T11:51:04Z")

</div>

ok understand

just to be sure did you double check the docs:  
[https://docs.confluent.io/cloud/current/client-apps/config-client.html#librdkafka-based-c-clients](https://docs.confluent.io/cloud/current/client-apps/config-client.html#librdkafka-based-c-clients)

especially

- In the Cloud Console, on the **Environment Overview** page, click **Clusters** and select your cluster from the list.
- From the navigation menu, click **Data In/Out → Clients**. Click **C/C++** and insert the following configuration settings into your client code.

---

<div class="post-metadata">

**Author:** ![yanming-li](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/yanming-li/32/1214_2.png) [@yanming-li](https://forum.confluent.io/u/yanming-li)\
**Post date:** [21 October 2021 17:34 UTC](https://forum.confluent.io/t/sasl-authentication-error-when-connect-to-confluent-cloud/3111/7 "2021-10-21T17:34:27Z")

</div>

Using key/secret generated by ccloud cli helped me resolve the issue.  
Thanks for your tips
