Review TLS enforcement for Azure PostgreSQL

Require TLS connections to Azure PostgreSQL and verify the server certificate.

Description

If PostgreSQL permits unencrypted connections, database requests and responses can be exposed in transit. Current Flexible Server uses require_secure_transport instead of the historical Single Server property sslEnforcement.

Potential impact

An actor intercepting the connection can read or alter queries and results. Transport encryption is needed separately from database authentication.

Remediation

Set require_secure_transport to on on Flexible Server. Configure clients to use TLS and verify the server certificate, and check existing application connections.

Examples

The initial excerpt is historical configuration for the retired Single Server service. Supply administratorPassword through a separate secure parameter. In the revised excerpt, MyDBServer refers to a prepared Flexible Server; server declarations and data migration are separate.

Before

bicep
resource MyDBServer 'Microsoft.DBforPostgreSQL/servers@2017-12-01' = {
  name: 'mydbserver'
  properties: {
    createMode: 'Default'
    sslEnforcement: 'Disabled'
    version: '11'
    administratorLogin: 'pgadmin'
    administratorLoginPassword: administratorPassword
  }
}

sslEnforcement: 'Disabled' did not require TLS on the historical service.

After

bicep
resource MyDBServer_tls 'Microsoft.DBforPostgreSQL/flexibleServers/configurations@2024-08-01' = {
  parent: MyDBServer
  name: 'require_secure_transport'
  properties: {
    source: 'user-override'
    value: 'on'
  }
}

The secure-transport parameter is applied to an existing Flexible Server. This does not migrate data or configure clients.

References