Review the minimum TLS version for Azure PostgreSQL

Protect PostgreSQL connections with supported TLS versions and server certificate validation.

Description

Allowing obsolete TLS protocols can weaken protection for database connections. Current Azure PostgreSQL Flexible Server supports TLS 1.2 and TLS 1.3, with TLS 1.2 as the default minimum. Review the current service settings instead of carrying forward retired Single Server configuration.

Potential impact

  • Environments permitting obsolete protocols may not meet transport security requirements.
  • Changing the minimum version without checking clients can interrupt required connections.

Remediation

Keep require_secure_transport set to on on Flexible Server and set ssl_min_protocol_version to the supported TLSv1.2 or TLSv1.3 value. Verify client compatibility and server certificate validation. Migrate retired Single Server configurations to a supported service, planning data migration and connection changes separately.

Examples

The before example historically allowed TLS 1.1 on retired Single Server. Do not use it for current deployment. The after example configures only two TLS parameters on an existing Flexible Server; it is not a server migration procedure.

Before

hcl
resource "azurerm_postgresql_server" "example" {
  name                = "example-postgresql"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  sku_name            = "GP_Gen5_4"
  version             = "11"

  ssl_enforcement_enabled          = true
  ssl_minimal_tls_version_enforced = "TLS1_1"
}

After

hcl
resource "azurerm_postgresql_flexible_server_configuration" "require_tls" {
  name      = "require_secure_transport"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "on"
}

resource "azurerm_postgresql_flexible_server_configuration" "example" {
  name      = "ssl_min_protocol_version"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "TLSv1.2"
}

The after example requires encrypted connections and specifies TLS 1.2 as the minimum. This does not raise the version above the current default, and clients must also validate the server certificate.

References