Description
Disabling TLS enforcement on Azure PostgreSQL can allow unencrypted connections. The former Single Server service used enforce_ssl, while the current Flexible Server service uses require_secure_transport.
Potential impact
Database requests and responses sent in plaintext can be exposed or modified on the network.
Remediation
Keep require_secure_transport set to on on Flexible Server and configure clients to use TLS with server-certificate verification.
Examples
The initial excerpt is a historical setting for the retired Single Server service. The revised excerpt updates a parameter on an existing Flexible Server named testserver; server and data migration must be handled separately.
Before
yaml
- name: PostgreSQL 서버 생성
azure.azcollection.azure_rm_postgresqlserver:
resource_group: myResourceGroup
name: testserver
location: eastus
storage_mb: 5120
enforce_ssl: no
admin_username: cloudsa
admin_password: "{{ postgresql_admin_password }}"
no_log: true
After
yaml
- name: PostgreSQL TLS 설정
azure.azcollection.azure_rm_postgresqlflexibleconfiguration:
resource_group: myResourceGroup
server_name: testserver
name: require_secure_transport
value: "on"