Description
If PostgreSQL permits unencrypted connections, database requests and responses can be exposed in transit. Current Flexible Server uses require_secure_transport instead of the historical Single Server property sslEnforcement.
Potential impact
An actor intercepting the connection can read or alter queries and results. Transport encryption is needed separately from database authentication.
Remediation
Set require_secure_transport to on on Flexible Server. Configure clients to use TLS and verify the server certificate, and check existing application connections.
Examples
The initial excerpt is historical configuration for the retired Single Server service. Supply administratorPassword through a separate secure parameter. In the revised excerpt, MyDBServer refers to a prepared Flexible Server; server declarations and data migration are separate.
Before
resource MyDBServer 'Microsoft.DBforPostgreSQL/servers@2017-12-01' = {
name: 'mydbserver'
properties: {
createMode: 'Default'
sslEnforcement: 'Disabled'
version: '11'
administratorLogin: 'pgadmin'
administratorLoginPassword: administratorPassword
}
}
sslEnforcement: 'Disabled' did not require TLS on the historical service.
After
resource MyDBServer_tls 'Microsoft.DBforPostgreSQL/flexibleServers/configurations@2024-08-01' = {
parent: MyDBServer
name: 'require_secure_transport'
properties: {
source: 'user-override'
value: 'on'
}
}
The secure-transport parameter is applied to an existing Flexible Server. This does not migrate data or configure clients.