Azure Redis allows non-SSL connections

Disable the non-SSL port on Azure Redis and verify that clients use TLS.

Description

When enableNonSslPort is true, Azure Redis Cache accepts connections on an unencrypted port. Redis stores application state and cached data, so traffic needs protection even on a private network.

Potential impact

  • Non-SSL connections can expose cached data and credentials in plaintext.
  • An attacker with access to the traffic path may intercept or alter requests.

Remediation

Set enableNonSslPort to false. Check connection strings so applications and administrative tools use TLS, and keep the minimum TLS version aligned with your security requirements.

Examples

These Azure Native v2 excerpts show connection settings only. The resource group, SKU, and other cache settings are omitted.

Before

yaml
resources:
  redis:
    type: azure-native:cache:Redis
    properties:
      enableNonSslPort: true
      minimumTlsVersion: "1.2"

After

yaml
resources:
  redis:
    type: azure-native:cache:Redis
    properties:
      enableNonSslPort: false
      minimumTlsVersion: "1.2"

The change disables the non-SSL port. Migrate clients to TLS and verify connectivity first. Cache authentication and network access restrictions are still required.

References