Description
If Cloud SQL permits unencrypted connections, credentials and application data can be exposed in transit. Retain connection encryption and server-certificate validation even on private networks.
The current sslMode takes precedence over legacy requireSsl, so omitting requireSsl does not by itself establish that plaintext connections are allowed. Check the engine’s effective TLS mode together with client settings.
Potential impact
- Sensitive data may be intercepted on unprotected connections.
- Incorrect server-certificate validation can increase the risk of a man-in-the-middle attack.
Remediation
- Use a supported management tool to configure an encrypted-only mode appropriate for the engine. If client certificates are also required, prepare them before enforcement.
- Test application TLS and server verification. When using Cloud SQL Auth Proxy, protect the separate application-to-proxy connection too.
- Verify encryption on actual connections and restrict database permissions and network access.
Examples
Deployment Manager support has ended. These are legacy connection-setting excerpts for MySQL or PostgreSQL; supply the engine, Region and other configuration separately. For these engines, requireSsl: true also requires trusted client certificates, so prepare clients first.
Before
resources:
- name: sql-instance
type: sqladmin.v1beta4.instance
properties:
settings:
tier: db-custom-1-3840
No separate connection-encryption requirement is specified. Check the effective sslMode and actual client connections.
After
resources:
- name: sql-instance
type: sqladmin.v1beta4.instance
properties:
settings:
tier: db-custom-1-3840
ipConfiguration:
requireSsl: true
This enables legacy requireSsl. For MySQL/PostgreSQL, a jointly specified sslMode must use the compatible TRUSTED_CLIENT_CERTIFICATE_REQUIRED setting.