Description
A low minimum TLS version can allow older encrypted connections to a Function App. Use TLS 1.2 or later and consider TLS 1.3 when clients support it. New apps default to TLS 1.2, so omitting the setting alone does not establish weak encryption.
Potential impact
- Older TLS connections may be permitted.
- Organizational transport encryption requirements may not be met.
- The function and SCM endpoints may have different protection levels.
Remediation
Set an approved minimum version using site_config.min_tls_version or site_config.minimum_tls_version for the resource type. Review the current resource’s SCM TLS setting and HTTPS enforcement separately. Check client compatibility before the change and test permitted and rejected connections afterward.
Examples
The before excerpt uses the legacy AzureRM 3.x Function App; the after excerpt uses the current Linux Function App. Required resource group and storage settings are omitted. Moving between resource types requires reviewing existing state and app configuration, not just changing a TLS value.
Before
resource "azurerm_function_app" "example" {
name = "test-azure-functions"
location = azurerm_resource_group.example.location
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
min_tls_version = "1.1"
}
}
After
resource "azurerm_linux_function_app" "example" {
name = "test-azure-functions"
location = azurerm_resource_group.example.location
service_plan_id = azurerm_service_plan.example.id
site_config {
minimum_tls_version = "1.3"
}
}
The before example uses a minimum TLS version of 1.1. The after example requires 1.3, rejecting older TLS clients. Apply it after checking the approved requirements and compatibility.