Description
An unencrypted database connection can expose credentials, queries and returned data to an attacker with access to the network path. Use SSL/TLS for Cloud SQL connections and configure clients to verify the server's identity.
Cloud SQL gives sslMode precedence over the legacy requireSsl setting. For MySQL and PostgreSQL, ENCRYPTED_ONLY with requireSsl: false still allows only encrypted connections. SQL Server pairs ENCRYPTED_ONLY with requireSsl: true. The TRUSTED_CLIENT_CERTIFICATE_REQUIRED mode additionally requires client certificates and is available for MySQL and PostgreSQL, but not SQL Server.
Potential impact
- Unencrypted connections can expose credentials or business data.
- Clients that do not verify the server's identity risk connecting to an unintended server.
Remediation
- Apply the appropriate SSL/TLS mode for the engine through the Cloud SQL console or supported administration tooling/API. If the legacy
requireSslsetting is also used, choose a compatible value. Prepare client TLS settings and any required certificates first. - The SQL instance module in
google.cloud1.14.0 providesrequire_sslbut notssl_mode, and cannot update existing objects. Use another supported administration method to change an existing instance's mode. - Review the entire path from the application to the instance. Cloud SQL Auth Proxy encrypts the proxy-to-instance connection, but does not automatically encrypt the application-to-proxy segment. Verify that required connections work and disallowed unencrypted connections are rejected.
Examples
These examples compare the legacy require_ssl option. They omit the engine and SSL mode, so check compatibility with the actual environment. The 8.8.8.8/32 entry and google dns server label are not values to use for an allow-list of real database clients.
First configuration
- name: create a forth instance
google.cloud.gcp_sql_instance:
name: "{{ resource_name }}-2"
settings:
ip_configuration:
require_ssl: no
authorized_networks:
- name: google dns server
value: 8.8.8.8/32
tier: db-n1-standard-1
region: us-central1
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
The legacy option does not require encryption when set to require_ssl: no. Whether the current configuration enforces encrypted connections also depends on the applied sslMode.
Comparison configuration
- name: create a instance
google.cloud.gcp_sql_instance:
name: '{{ resource_name }}-2'
settings:
ip_configuration:
require_ssl: yes
authorized_networks:
- name: google dns server
value: 8.8.8.8/32
tier: db-n1-standard-1
region: us-central1
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
This configuration enables the legacy option with require_ssl: yes. Choose an engine-compatible SSL mode, prepare any required client certificates, and verify the settings applied to the actual instance.
References
- CWE-732
- Ansible gcp_sql_instance require_ssl documentation
- google.cloud 1.14.0 SQL instance module implementation
- Cloud SQL API IpConfiguration and SSL mode compatibility
- Cloud SQL for MySQL SSL/TLS configuration
- Cloud SQL for PostgreSQL SSL/TLS configuration
- Cloud SQL for SQL Server SSL/TLS configuration
- Cloud SQL Auth Proxy connection protection