Description
In Crossplane's Azure Redis configuration, enableNonSslPort: true allows connections without TLS. Redis can hold session data, cached user information and data shared between internal services, so encryption in transit is important.
This setting does not turn every connection into plaintext, but clients using the non-TLS port send unencrypted data. Configure clients to use TLS and verify the server certificate even on an internal network.
Potential impact
- An attacker able to observe network traffic could obtain data or credentials sent over an unencrypted connection.
- An attacker able to manipulate that traffic path could also threaten data integrity.
Remediation
- Migrate clients to TLS first, and configure server certificate and hostname verification.
- Explicitly set
enableNonSslPorttofalseto disable the unencrypted port. - Retain authentication and network access restrictions, and test that legitimate TLS connections succeed while unencrypted connections are rejected.
Examples
These partial examples compare the non-TLS port setting. Other settings required to create the cache are omitted.
Before
apiVersion: cache.azure.crossplane.io/v1beta1
kind: Redis
spec:
forProvider:
location: West Europe
enableNonSslPort: true
The non-TLS port is enabled, so clients can use unencrypted connections.
After
apiVersion: cache.azure.crossplane.io/v1beta1
kind: Redis
spec:
forProvider:
location: West Europe
enableNonSslPort: false
The non-TLS port is disabled. Application connection settings must also use TLS to retain connectivity.