Description
Enabling enable_non_ssl_port on Redis Cache allows clients to connect through an unencrypted port.
Potential impact
Cached data and authentication information sent over that connection can be exposed on the network.
Remediation
Confirm that clients can connect over TLS, then set enable_non_ssl_port to no. Enable server-certificate verification on clients too.
Examples
The examples compare only the non-TLS port setting. Configure connection addresses, the TLS port, and clients separately.
Before
yaml
- name: Redis 생성
azure_rm_rediscache:
resource_group: myResourceGroup
name: myRedis
enable_non_ssl_port: yes
After
yaml
- name: Redis 생성
azure_rm_rediscache:
resource_group: myResourceGroup
name: myRedis
enable_non_ssl_port: no