Description
Enabling the non-TLS port in Azure Cache for Redis lets clients that can reach that port use connections without TLS. Redis can hold sensitive sessions, tokens and cache data, so plaintext connections can expose data and credentials.
Potential impact
- Cache data and credentials on unencrypted connections can be exposed on the network.
- An attacker able to observe or modify the traffic path may steal sessions or tokens.
Remediation
Disable the non-TLS port with non_ssl_port_enabled = false in the current provider, or enable_non_ssl_port = false in AzureRM 3.117.1. Configure applications and operational tools to use TLS and validate the server certificate; also verify the minimum TLS version and network access.
Examples
These examples use the enable_non_ssl_port argument from AzureRM 3.117.1. Its current-provider counterpart is non_ssl_port_enabled. Configure referenced resources separately.
Before
resource "azurerm_redis_cache" "example" {
name = "example-cache"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
capacity = 2
family = "C"
sku_name = "Standard"
enable_non_ssl_port = true
minimum_tls_version = "1.2"
redis_configuration {
}
}
After
resource "azurerm_redis_cache" "example" {
name = "example-cache"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
capacity = 2
family = "C"
sku_name = "Standard"
enable_non_ssl_port = false
minimum_tls_version = "1.2"
redis_configuration {
}
}
The after example disables the non-TLS port. Update clients to use the TLS port while retaining authentication and access permissions.