Redis Cache permits unencrypted connections

Disable the non-TLS port and move Redis Cache clients to TLS.

Description

Enabling enable_non_ssl_port on Redis Cache allows clients to connect through an unencrypted port.

Potential impact

Cached data and authentication information sent over that connection can be exposed on the network.

Remediation

Confirm that clients can connect over TLS, then set enable_non_ssl_port to no. Enable server-certificate verification on clients too.

Examples

The examples compare only the non-TLS port setting. Configure connection addresses, the TLS port, and clients separately.

Before

yaml
- name: Redis 생성
  azure_rm_rediscache:
    resource_group: myResourceGroup
    name: myRedis
    enable_non_ssl_port: yes

After

yaml
- name: Redis 생성
  azure_rm_rediscache:
    resource_group: myResourceGroup
    name: myRedis
    enable_non_ssl_port: no

References