Description
Redis sessions, tokens and cache data need protection in transit. Azure Cache for Redis rejects TLS 1.0 and TLS 1.1 connections, and minimum_tls_version defaults to 1.2 in AzureRM 5.6.0. Omitting this argument does not by itself allow obsolete TLS.
Potential impact
- Clients using obsolete protocols may fail to connect to the current service.
- Unencrypted connections or missing server certificate validation can increase exposure of data and credentials.
Remediation
Set minimum_tls_version = "1.2" explicitly and disable the non-TLS port. Verify that applications support TLS 1.2 or later and configure TLS connections with server certificate validation.
Examples
The TLS 1.1 value in the before example is unsupported by the current service and AzureRM 5.6.0; do not use it for deployment. The after example explicitly selects a supported minimum version.
Before
resource "azurerm_redis_cache" "example" {
name = "example-cache"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
capacity = 2
family = "C"
sku_name = "Standard"
non_ssl_port_enabled = false
minimum_tls_version = "1.1"
}
After
resource "azurerm_redis_cache" "example" {
name = "example-cache"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
capacity = 2
family = "C"
sku_name = "Standard"
non_ssl_port_enabled = false
minimum_tls_version = "1.2"
}
The after example sets the minimum TLS version to 1.2. The current default is also 1.2, so omitting the argument does not necessarily weaken encryption.