All Products
Search
Document Center

Data Management:FAQ about database logon

Last Updated:Aug 27, 2026

This topic provides answers to frequently asked questions about logging on to a database in the Data Management (DMS) console.

How do I enter the valid database account and password?

The database account is the user account. The database password is the password of the user account. The following steps show how to log on to a database in the DMS console. In this example, an ApsaraDB RDS for MySQL instance is used.

  1. Obtain the database account and password.

    1. Go to the Instances page in the ApsaraDB RDS console, find the instance to which you want to log on, and then click its name.

    2. In the left-side navigation pane, click Accounts to view the account name.

      Note

      If you forget the password, click Reset Password in the Actions column of the account. For more information, see Reset the password of an account on an ApsaraDB RDS for MySQL instance.

  2. Log on to the database.

    1. In the upper part of the instance details page, click Log On to Database. You are navigated to the DMS console. The Log on to Database Instance dialog box appears.

    2. Enter the account name in the Database Account field.

    3. Enter the password in the Database Password field.

      Note

      Type the password manually. Do not copy and paste it.

    4. Click Login.

What do I do if I fail to log on to the database in DMS and the message indicating that the database access is denied appears?

This error occurs for the following reasons:

  • The database account or password is invalid.

    In this case, re-enter the database account and password and then click Login.

  • The current account does not have the required permissions on databases.

    In this case, check whether your account has database permissions. If not, contact the administrator to grant database permissions to your account.

  • The instance cannot be accessed from the current IP address.

    In this case, you must allow the current IP address to be used to access the instance or add the IP addresses and CIDR blocks of DMS to the IP address whitelist of the database instance. For more information, see Authorize an account to access its authorized databases from specified IP addresses or Add DMS IP address ranges.

Why does DMS say "Failed to establish the connection, which may be due to an invalid database password, incorrect whitelist settings, or improper configuration of instance logon-free mode"?

Check the three most common causes in order:

  1. Verify the database account password is correct.

  2. Verify the DMS IP addresses are added to the instance whitelist. For the full list of IP addresses and CIDR blocks, see Add DMS IP addresses and CIDR blocks to security settings.

  3. Check whether security hosting (password-free logon) is enabled for the instance in DMS.

If the issue persists, try logging on using the endpoint of the instance directly, or remove the instance from DMS and try to log on to the instance again.

What do I do if the SSL certificate expires?

If the SSL certificate expires, update the expiration time. For more information, see Use a cloud certificate to enable SSL encryption.

DatabaseReference
ApsaraDB RDS for MySQLUse a cloud certificate to enable SSL encryption
ApsaraDB RDS for PostgreSQLConfigure a custom certificate to enable the SSL encryption feature
ApsaraDB for RedisConfigure SSL encryption

What do I do if I am prompted a whitelist issue when I register an ApsaraDB instance in DMS?

You can click Configure Whitelist in the Whitelist issues dialog box. DMS automatically adds the IP address of the DMS server to the whitelist of the ApsaraDB instance. If the IP address fails to be automatically added to the whitelist, you need to manually add it to the whitelist. For more information, see Add DMS IP address ranges.

Why does DMS say "the instance has been disabled"?

The Security Collaboration mode purchased for the instance has expired. Handle this based on your requirements:

  • To continue using Security Collaboration mode: Purchase the mode again, then log on to the instance. For details, see Purchase a feature of DMS.

  • To switch to a different control mode: In the DMS console, right-click the instance in the left-side navigation pane and choose Control Mode > Flexible Management. Then log on to the instance again.

What do I do if I fail to log on to an ApsaraDB for Redis instance in DMS and the system prompts "SSL connection must be used" or "Unexpected end of stream" after I enable TLS or SSL encryption for the instance?

The ApsaraDB for Redis instance has TLS encryption enabled, but DMS has not enabled SSL by default. This causes a TLS handshake failure at the connection layer. Choose one of the following solutions:

Solution 1: Enable SSL for the instance in DMS.

  1. Log in to DMS 5.0.

  2. On the Home page of the DMS console, choose Database Instance > Instances Disconnected in the left-side navigation pane. In the instance list that appears, right-click the ApsaraDB for Redis instance to which you want to log on and click Edit.

  3. In the Advanced Information section of the Edit dialog box, set the Enable SSL parameter to Enable.

  4. Click Test Connection.

  5. After the connection test is passed, click Save. The database instance is connected to DMS.

Solution 2: Disable TLS encryption for the ApsaraDB for Redis instance.

In the ApsaraDB for Redis console, go to the TLS (SSL) settings page and disable TLS encryption. After TLS is disabled, the instance restarts. We recommend that you perform this operation during off-peak hours. After the instance restarts, you can log on to the database in DMS with default configurations.

For more information about enabling SSL in DMS, see Edit instance information.

What do I do if I fail to log on to a database in DMS and the message indicating that the access source is invalid appears?

If you use a Resource Access Management (RAM) user, perform the following steps to troubleshoot the issue:

  1. Check whether you have authorized DMS to access your resources as the RAM user. If you have not authorized DMS to access your resources as the RAM user, complete the authorization on the Cloud Resource Access Authorization page.

  2. Add the IP addresses of DMS to the IP address whitelist of the database instance. For more information, see Add DMS IP address ranges.

  3. Refresh the page and log on again.

What do I do if the following error message occurs when I log on to an ApsaraDB RDS instance?

NULL: 
com.ali.idbcloud.commons.multi.instance.session
service.AbstractAliyunWhiteListUserSessionServi
ce.throwConnectDBFailReason(AbstractAliyunWhite
ListUserSessionService.java:97)com.ali.idbcloud
.commons.multi.instance.sessionservice.BaseUser
SessionService.doLoginCore(BaseUserSessionServi
ce.java:924)com.ali.idbcloud.commons.multi.inst
ance.sessionservice.BaseUserSessionService.worl
dLogin(BaseUserSessionService.java:968)

In most cases, this error occurs in the old version of DMS Personal Edition. The old version of DMS Personal Edition is discontinued. To go to the DMS console of the new version, click Go to New DMS in the upper-right corner of the page.

What do I do if I fail to log on to an ApsaraDB RDS for MySQL instance and the system prompts that the instance does not exist?

Log on to the ApsaraDB RDS console. On the Instances page, check whether the instance to which you want to log on is in the normal state. If the instance status is normal, refresh the DMS console to synchronize the metadata of the instance. If the instance status is abnormal, troubleshoot the issue.

Warning

Restart the instance on the premise that your business is not affected. If you restart the instance, a connection interruption that lasts approximately 30 seconds occurs. Proceed with caution.

What do I do if the system prompts that I temporarily cannot access the instance by using DMS?

This error occurs because the instance owner or DMS administrator does not grant permissions on instance logon to your account. In this case, contact the DMS administrator to grant permissions on instance logon to your account. For more information, see the Manage permissions as a DMS administrator section of the "Manage permissions" topic.

Why does DMS say "InvalidDBInstanceName.NotFound: The specified DB instance name does not exist"?

Go to the instance console and verify that the instance exists and the instance name is correct. If the instance is running properly and the name is correct, contact DMS technical support.

What do I do if the "Communications link failure" message appears and the time consumed for connection is displayed when DMS connects to a MySQL database?

  • If the time consumed for connection is 0 milliseconds, the "Communications link failure" error may occur for the following reasons: the database account or password is invalid, no whitelist is configured, and the whitelist is incorrectly configured. For more information about how to configure an IP address whitelist, see Add DMS IP address ranges.

  • If the time consumed for connection is a few milliseconds or tens of milliseconds, check whether SSL is enabled for the instance and whether the SSL certificate expires.

How do I switch the database account in DMS, or fix logon and operation failures caused by insufficient account permissions or authentication errors?

Choose the scenario that matches your issue:

  • Switch to a different database account: In the left-side Instances Connected list of the DMS console, right-click the target instance and click Edit. Change the access mode to manual credential entry, enter the new database account and password, and then click Save.

  • Fix the "FATAL: no PostgreSQL user name specified in startup packet" error: In the DMS console, right-click the target instance and click Edit. Change the access mode to manual credential entry, enter the instance account and password that you created on the Accounts page of the ApsaraDB RDS console, and then click Save.

  • DMS shows only table schemas and no data after you create a PolarDB instance from a backup: This issue is usually caused by an authentication failure due to insufficient permissions. Create a privileged account in the PolarDB console. Then, in the DMS console, right-click the instance, click Edit, change the access mode to manual credential entry, enter the privileged account and password, and then click Save.

  • Database operations fail or table data cannot be queried: Check the access mode of the instance in DMS. If logon-free mode is enabled, right-click the instance, click Edit, and change the access mode to unmanaged or manual credential entry. Then, close DMS and log on again from the console with a privileged account. Also verify that you use the correct three-part name format, such as [database].[schema].[table].

Can I still download and use the DMS client?

No. The DMS client is no longer maintained, and Alibaba Cloud no longer provides a download link for it. Log on to DMS 5.0 in your browser to manage your databases instead. The web console supports all features and is more stable.

What do I do if an error that mentions the IP address 100.100.79.145 appears when I edit a table of an ApsaraDB RDS instance in DMS?

This error is usually caused by an abnormal connection state. Perform the following steps to troubleshoot the issue:

  1. In the left-side instance list of the DMS console, right-click the target instance and click Test Connectivity to verify that the connection works.

  2. After the connection test passes, run a simple query in the SQL console to verify that the feature works. In most cases, the issue resolves itself.

  3. If the issue persists, check the whitelist of the instance and confirm that the IP addresses of DMS are added to it.

What do I do if I cannot log on to or operate an ApsaraDB RDS read-only instance that is already registered with DMS?

Check which of the following situations applies:

  • Permission issue: A RAM user must be granted permissions on a specific instance before the RAM user can log on to a read-only instance. Contact the administrator of the Alibaba Cloud account to grant the required permissions.

  • Operations on a secondary node: A secondary node does not require separate authorization or logon. Log on to the primary instance, and then select the secondary node from the instance drop-down list in the upper part of the SQL console to run SQL statements.