Redis allows unencrypted connections

Allowing the non-TLS Redis port lets clients transmit cache data and credentials without encryption.

Description

In Crossplane's Azure Redis configuration, enableNonSslPort: true allows connections without TLS. Redis can hold session data, cached user information and data shared between internal services, so encryption in transit is important.

This setting does not turn every connection into plaintext, but clients using the non-TLS port send unencrypted data. Configure clients to use TLS and verify the server certificate even on an internal network.

Potential impact

  • An attacker able to observe network traffic could obtain data or credentials sent over an unencrypted connection.
  • An attacker able to manipulate that traffic path could also threaten data integrity.

Remediation

  • Migrate clients to TLS first, and configure server certificate and hostname verification.
  • Explicitly set enableNonSslPort to false to disable the unencrypted port.
  • Retain authentication and network access restrictions, and test that legitimate TLS connections succeed while unencrypted connections are rejected.

Examples

These partial examples compare the non-TLS port setting. Other settings required to create the cache are omitted.

Before

yaml
apiVersion: cache.azure.crossplane.io/v1beta1
kind: Redis
spec:
  forProvider:
    location: West Europe
    enableNonSslPort: true

The non-TLS port is enabled, so clients can use unencrypted connections.

After

yaml
apiVersion: cache.azure.crossplane.io/v1beta1
kind: Redis
spec:
  forProvider:
    location: West Europe
    enableNonSslPort: false

The non-TLS port is disabled. Application connection settings must also use TLS to retain connectivity.

References