Description
Without TLS enforcement, MySQL queries and responses can travel unencrypted. The historical Azure Single Server property sslEnforcement differs from require_secure_transport on current Flexible Server.
Potential impact
An actor able to intercept traffic can read or alter database requests and responses. An internal network does not replace transport protection.
Remediation
Keep require_secure_transport set to ON on Flexible Server. Configure applications to use TLS and verify the server certificate, then confirm that required connections still work.
Examples
The initial excerpt is historical Single Server configuration for a retired service; sourceServerId represents its restore-source resource ID. In the revised excerpt, server refers to a separately prepared Flexible Server. Server declarations and data migration are separate; this code does not perform migration.
Before
resource server 'Microsoft.DBforMySQL/servers@2017-12-01' = {
name: 'server'
properties: {
version: '5.6'
createMode: 'GeoRestore'
sourceServerId: sourceServerId
}
}
Omitting sslEnforcement alone does not establish that the actual server permitted plaintext connections.
After
resource server_tls 'Microsoft.DBforMySQL/flexibleServers/configurations@2024-12-30' = {
parent: server
name: 'require_secure_transport'
properties: {
source: 'user-override'
value: 'ON'
}
}
The Flexible Server secure-transport parameter is explicit. Retain server-certificate verification in client connection settings separately.