Description
Without TLS enforcement, Azure MySQL can accept unencrypted database connections. The former Single Server setting enforce_ssl differs from require_secure_transport in the current Flexible Server service.
Potential impact
Queries and result data sent over an unencrypted connection can be exposed or modified on the network.
Remediation
Set require_secure_transport to ON on Flexible Server and configure clients to use TLS and verify the server certificate.
Examples
The initial excerpt is a historical setting for the retired Single Server service. The revised excerpt configures TLS enforcement on an existing Flexible Server named testserver; it does not migrate a server or its data.
Before
yaml
- name: MySQL 서버 생성
azure.azcollection.azure_rm_mysqlserver:
resource_group: myResourceGroup
name: testserver
location: eastus
storage_mb: 5120
enforce_ssl: false
version: "5.6"
admin_username: cloudsa
admin_password: "{{ mysql_admin_password }}"
no_log: true
After
yaml
- name: MySQL TLS 설정
azure.azcollection.azure_rm_mysqlflexibleconfiguration:
resource_group: myResourceGroup
server_name: testserver
name: require_secure_transport
value: "ON"