Cloud SQL connection encryption settings need review

Require encrypted database connections and verify that clients validate the server certificate.

Description

If Cloud SQL permits unencrypted connections, credentials and application data can be exposed in transit. Retain connection encryption and server-certificate validation even on private networks.

The current sslMode takes precedence over legacy requireSsl, so omitting requireSsl does not by itself establish that plaintext connections are allowed. Check the engine’s effective TLS mode together with client settings.

Potential impact

  • Sensitive data may be intercepted on unprotected connections.
  • Incorrect server-certificate validation can increase the risk of a man-in-the-middle attack.

Remediation

  • Use a supported management tool to configure an encrypted-only mode appropriate for the engine. If client certificates are also required, prepare them before enforcement.
  • Test application TLS and server verification. When using Cloud SQL Auth Proxy, protect the separate application-to-proxy connection too.
  • Verify encryption on actual connections and restrict database permissions and network access.

Examples

Deployment Manager support has ended. These are legacy connection-setting excerpts for MySQL or PostgreSQL; supply the engine, Region and other configuration separately. For these engines, requireSsl: true also requires trusted client certificates, so prepare clients first.

Before

yaml
resources:
  - name: sql-instance
    type: sqladmin.v1beta4.instance
    properties:
      settings:
        tier: db-custom-1-3840

No separate connection-encryption requirement is specified. Check the effective sslMode and actual client connections.

After

yaml
resources:
  - name: sql-instance
    type: sqladmin.v1beta4.instance
    properties:
      settings:
        tier: db-custom-1-3840
        ipConfiguration:
          requireSsl: true

This enables legacy requireSsl. For MySQL/PostgreSQL, a jointly specified sslMode must use the compatible TRUSTED_CLIENT_CERTIFICATE_REQUIRED setting.

References