Description
When enableNonSslPort is true, Azure Redis Cache accepts connections on an unencrypted port. Redis stores application state and cached data, so traffic needs protection even on a private network.
Potential impact
- Non-SSL connections can expose cached data and credentials in plaintext.
- An attacker with access to the traffic path may intercept or alter requests.
Remediation
Set enableNonSslPort to false. Check connection strings so applications and administrative tools use TLS, and keep the minimum TLS version aligned with your security requirements.
Examples
These Azure Native v2 excerpts show connection settings only. The resource group, SKU, and other cache settings are omitted.
Before
yaml
resources:
redis:
type: azure-native:cache:Redis
properties:
enableNonSslPort: true
minimumTlsVersion: "1.2"
After
yaml
resources:
redis:
type: azure-native:cache:Redis
properties:
enableNonSslPort: false
minimumTlsVersion: "1.2"
The change disables the non-SSL port. Migrate clients to TLS and verify connectivity first. Cache authentication and network access restrictions are still required.