Description
HTTP/2 provides features such as multiplexing that improve web request efficiency. Disabling HTTP/2 does not establish that traffic is unencrypted: HTTP/1.1 can also use HTTPS. Choose the transport protocol according to service requirements and client support.
Potential impact
- The application may not benefit from HTTP/2 transport efficiencies.
- Protocol settings can differ from organizational operating standards.
- Changing settings without compatibility checks can affect some clients.
Remediation
Where HTTP/2 is needed, set site_config.http2_enabled = true and verify client support and actual protocol negotiation. Configure HTTPS, the minimum TLS version and authentication separately. If client certificates are used, also check compatibility with settings that require TLS renegotiation.
Examples
These are excerpts of a legacy AzureRM 3.x Function App; required storage configuration is omitted. The runtime settings shown do not recommend a version for current deployment.
Before
resource "azurerm_function_app" "example" {
name = "test-azure-functions"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
}
After
resource "azurerm_function_app" "example" {
name = "test-azure-functions"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
http2_enabled = true
}
}
The before example does not enable HTTP/2. The after example sets http2_enabled = true. Actual HTTP/2 use depends on negotiation with the client, and this setting alone does not enforce HTTPS.