TLS enforcement is disabled for Azure MySQL

Require TLS for Azure MySQL connections and verify the server certificate on clients.

Description

Without TLS enforcement, Azure MySQL can accept unencrypted database connections. The former Single Server setting enforce_ssl differs from require_secure_transport in the current Flexible Server service.

Potential impact

Queries and result data sent over an unencrypted connection can be exposed or modified on the network.

Remediation

Set require_secure_transport to ON on Flexible Server and configure clients to use TLS and verify the server certificate.

Examples

The initial excerpt is a historical setting for the retired Single Server service. The revised excerpt configures TLS enforcement on an existing Flexible Server named testserver; it does not migrate a server or its data.

Before

yaml
- name: MySQL 서버 생성
  azure.azcollection.azure_rm_mysqlserver:
    resource_group: myResourceGroup
    name: testserver
    location: eastus
    storage_mb: 5120
    enforce_ssl: false
    version: "5.6"
    admin_username: cloudsa
    admin_password: "{{ mysql_admin_password }}"
  no_log: true

After

yaml
- name: MySQL TLS 설정
  azure.azcollection.azure_rm_mysqlflexibleconfiguration:
    resource_group: myResourceGroup
    server_name: testserver
    name: require_secure_transport
    value: "ON"

References