Azure Redis allows unencrypted connections

Disable the non-TLS port and configure applications to use TLS connections.

Description

Enabling the non-TLS port in Azure Cache for Redis lets clients that can reach that port use connections without TLS. Redis can hold sensitive sessions, tokens and cache data, so plaintext connections can expose data and credentials.

Potential impact

  • Cache data and credentials on unencrypted connections can be exposed on the network.
  • An attacker able to observe or modify the traffic path may steal sessions or tokens.

Remediation

Disable the non-TLS port with non_ssl_port_enabled = false in the current provider, or enable_non_ssl_port = false in AzureRM 3.117.1. Configure applications and operational tools to use TLS and validate the server certificate; also verify the minimum TLS version and network access.

Examples

These examples use the enable_non_ssl_port argument from AzureRM 3.117.1. Its current-provider counterpart is non_ssl_port_enabled. Configure referenced resources separately.

Before

hcl
resource "azurerm_redis_cache" "example" {
  name                = "example-cache"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  capacity            = 2
  family              = "C"
  sku_name            = "Standard"
  enable_non_ssl_port = true
  minimum_tls_version = "1.2"

  redis_configuration {
  }
}

After

hcl
resource "azurerm_redis_cache" "example" {
  name                = "example-cache"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  capacity            = 2
  family              = "C"
  sku_name            = "Standard"
  enable_non_ssl_port = false
  minimum_tls_version = "1.2"

  redis_configuration {
  }
}

The after example disables the non-TLS port. Update clients to use the TLS port while retaining authentication and access permissions.

References