Description
Azure Storage requires at least TLS 1.2. Replace obsolete TLS1_0 settings with an explicit minimum_tls_version: TLS1_2 value to reflect current requirements.
Potential impact
Clients that depend on TLS 1.0 or 1.1 can fail to connect to the current service. Obsolete settings also obscure the actual connection requirements.
Remediation
Set minimum_tls_version to TLS1_2 and confirm clients support TLS 1.2 or later. Require HTTPS as well.
Examples
The initial TLS1_0 value is a historical setting, not a way to permit TLS 1.0 on the current service. The revised value states the supported minimum.
Before
yaml
- name: Storage Account 생성
azure_rm_storageaccount:
resource_group: myResourceGroup
name: clh0002
type: Premium_LRS
kind: FileStorage
minimum_tls_version: TLS1_0
After
yaml
- name: Storage Account 생성
azure_rm_storageaccount:
resource_group: myResourceGroup
name: clh0002
type: Premium_LRS
kind: FileStorage
minimum_tls_version: TLS1_2