Review TLS enforcement for Azure MySQL

Require TLS for Azure MySQL connections and validate the server certificate on clients.

Description

A MySQL server that permits unencrypted connections can expose credentials and data in transit. An internal network does not replace TLS protection. Current Flexible Server uses require_secure_transport instead of the legacy Single Server ssl_enforcement_enabled setting.

Potential impact

  • Unencrypted requests and query results can be intercepted or modified.
  • Transport encryption requirements may not be met.

Remediation

Keep require_secure_transport set to ON on Flexible Server. Configure applications and operational tools to use TLS and server certificate validation, then verify that required connections still work. Also limit network access and database permissions to what is needed.

Examples

The before example is a historical Single Server configuration; that service retired in 2025. Do not use it for current deployment. The after example configures a TLS parameter on an existing Flexible Server; plan server migration separately.

Before

hcl
resource "azurerm_mysql_server" "example" {
  name                = "webflux-mysql-${var.environment}${random_integer.rnd_int.result}"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  administrator_login          = "webflux-${var.environment}"
  administrator_login_password = random_string.password.result

  sku_name   = "B_Gen5_2"
  storage_mb = 5120
  version    = "5.7"

  auto_grow_enabled                 = true
  backup_retention_days             = 7
  infrastructure_encryption_enabled = true
  public_network_access_enabled     = true
  ssl_enforcement_enabled           = false
}

After

hcl
resource "azurerm_mysql_flexible_server_configuration" "example" {
  name                = "require_secure_transport"
  resource_group_name = azurerm_resource_group.example.name
  server_name         = azurerm_mysql_flexible_server.example.name
  value               = "ON"
}

The before example does not enforce SSL connections. The after example requires encrypted connections on the current server. Clients must also continue to validate the server certificate.

References