Description
A MySQL server that permits unencrypted connections can expose credentials and data in transit. An internal network does not replace TLS protection. Current Flexible Server uses require_secure_transport instead of the legacy Single Server ssl_enforcement_enabled setting.
Potential impact
- Unencrypted requests and query results can be intercepted or modified.
- Transport encryption requirements may not be met.
Remediation
Keep require_secure_transport set to ON on Flexible Server. Configure applications and operational tools to use TLS and server certificate validation, then verify that required connections still work. Also limit network access and database permissions to what is needed.
Examples
The before example is a historical Single Server configuration; that service retired in 2025. Do not use it for current deployment. The after example configures a TLS parameter on an existing Flexible Server; plan server migration separately.
Before
resource "azurerm_mysql_server" "example" {
name = "webflux-mysql-${var.environment}${random_integer.rnd_int.result}"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
administrator_login = "webflux-${var.environment}"
administrator_login_password = random_string.password.result
sku_name = "B_Gen5_2"
storage_mb = 5120
version = "5.7"
auto_grow_enabled = true
backup_retention_days = 7
infrastructure_encryption_enabled = true
public_network_access_enabled = true
ssl_enforcement_enabled = false
}
After
resource "azurerm_mysql_flexible_server_configuration" "example" {
name = "require_secure_transport"
resource_group_name = azurerm_resource_group.example.name
server_name = azurerm_mysql_flexible_server.example.name
value = "ON"
}
The before example does not enforce SSL connections. The after example requires encrypted connections on the current server. Clients must also continue to validate the server certificate.