Description
Allowing obsolete TLS protocols can weaken protection for database connections. Current Azure PostgreSQL Flexible Server supports TLS 1.2 and TLS 1.3, with TLS 1.2 as the default minimum. Review the current service settings instead of carrying forward retired Single Server configuration.
Potential impact
- Environments permitting obsolete protocols may not meet transport security requirements.
- Changing the minimum version without checking clients can interrupt required connections.
Remediation
Keep require_secure_transport set to on on Flexible Server and set ssl_min_protocol_version to the supported TLSv1.2 or TLSv1.3 value. Verify client compatibility and server certificate validation. Migrate retired Single Server configurations to a supported service, planning data migration and connection changes separately.
Examples
The before example historically allowed TLS 1.1 on retired Single Server. Do not use it for current deployment. The after example configures only two TLS parameters on an existing Flexible Server; it is not a server migration procedure.
Before
resource "azurerm_postgresql_server" "example" {
name = "example-postgresql"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
sku_name = "GP_Gen5_4"
version = "11"
ssl_enforcement_enabled = true
ssl_minimal_tls_version_enforced = "TLS1_1"
}
After
resource "azurerm_postgresql_flexible_server_configuration" "require_tls" {
name = "require_secure_transport"
server_id = azurerm_postgresql_flexible_server.example.id
value = "on"
}
resource "azurerm_postgresql_flexible_server_configuration" "example" {
name = "ssl_min_protocol_version"
server_id = azurerm_postgresql_flexible_server.example.id
value = "TLSv1.2"
}
The after example requires encrypted connections and specifies TLS 1.2 as the minimum. This does not raise the version above the current default, and clients must also validate the server certificate.