Description
A low minimum TLS version permits clients using older protocols. New App Service apps default to TLS 1.2, so omission alone does not imply that older TLS is allowed. TLS 1.3 is also supported; choose the minimum according to client compatibility and security policy.
Potential impact
- Allowing older TLS may violate the organization’s encryption requirements.
- Raising the minimum without compatibility checks can break existing client connections.
Remediation
Require at least TLS 1.2 on the app and SCM endpoints, and consider TLS 1.3 after confirming compatibility. Check minimum_tls_version and scm_minimum_tls_version on current resources and test actual connections. Use the corresponding version-specific fields for legacy resources.
Examples
The first excerpt uses the legacy AzureRM 3.x resource; the second uses a current Linux Web App. App Service plans to retire TLS 1.0 and 1.1 on May 31, 2027. Supply an actual Linux service plan ID for the current example.
Before
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
min_tls_version = "1.0"
}
}
After
resource "azurerm_linux_web_app" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
service_plan_id = var.service_plan_id
site_config {
minimum_tls_version = "1.3"
}
}
The second excerpt sets the app’s minimum to TLS 1.3. Changing resource types requires a separate migration plan, and the SCM endpoint’s TLS setting is not included here.