Description
A database that permits connections without TLS can transmit credentials, query results and application data in plaintext. Internal networks also need transport protection. PostgreSQL Flexible Server currently defaults require_secure_transport to on, so omitting the setting does not establish that encryption is disabled.
Potential impact
- Unencrypted database traffic can be exposed or altered on the network.
- Sensitive data may fail to meet transport-encryption requirements.
Remediation
Migrate retired Single Server deployments to supported PostgreSQL Flexible Server. Keep require_secure_transport set to on and verify application TLS connections and server certificate validation. Review minimum TLS versions and network access controls as well.
Examples
The before example is historical Single Server configuration for a retired service. Do not use it for new deployment or reuse its example password. The after excerpt shows only the transport-encryption parameter of a separately provisioned Flexible Server.
Before
resource "azurerm_postgresql_server" "example" {
name = "example-psqlserver"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
administrator_login = "psqladminun"
administrator_login_password = "H@Sh1CoR3!"
sku_name = "GP_Gen5_4"
version = "9.6"
storage_mb = 640000
backup_retention_days = 7
geo_redundant_backup_enabled = true
auto_grow_enabled = true
public_network_access_enabled = false
ssl_enforcement_enabled = false
ssl_minimal_tls_version_enforced = "TLS1_2"
}
After
resource "azurerm_postgresql_flexible_server_configuration" "example" {
name = "require_secure_transport"
server_id = azurerm_postgresql_flexible_server.example.id
value = "on"
}
The after example sets require_secure_transport to on. Perform server migration and data verification separately, and verify that clients use TLS and validate the correct server certificate.