Review the minimum TLS version for Azure Redis

Protect Redis connections with supported TLS versions and certificate validation.

Description

Redis sessions, tokens and cache data need protection in transit. Azure Cache for Redis rejects TLS 1.0 and TLS 1.1 connections, and minimum_tls_version defaults to 1.2 in AzureRM 5.6.0. Omitting this argument does not by itself allow obsolete TLS.

Potential impact

  • Clients using obsolete protocols may fail to connect to the current service.
  • Unencrypted connections or missing server certificate validation can increase exposure of data and credentials.

Remediation

Set minimum_tls_version = "1.2" explicitly and disable the non-TLS port. Verify that applications support TLS 1.2 or later and configure TLS connections with server certificate validation.

Examples

The TLS 1.1 value in the before example is unsupported by the current service and AzureRM 5.6.0; do not use it for deployment. The after example explicitly selects a supported minimum version.

Before

hcl
resource "azurerm_redis_cache" "example" {
  name                 = "example-cache"
  location             = azurerm_resource_group.example.location
  resource_group_name  = azurerm_resource_group.example.name
  capacity             = 2
  family               = "C"
  sku_name             = "Standard"
  non_ssl_port_enabled = false
  minimum_tls_version  = "1.1"
}

After

hcl
resource "azurerm_redis_cache" "example" {
  name                 = "example-cache"
  location             = azurerm_resource_group.example.location
  resource_group_name  = azurerm_resource_group.example.name
  capacity             = 2
  family               = "C"
  sku_name             = "Standard"
  non_ssl_port_enabled = false
  minimum_tls_version  = "1.2"
}

The after example sets the minimum TLS version to 1.2. The current default is also 1.2, so omitting the argument does not necessarily weaken encryption.

References