Review Azure PostgreSQL connection encryption

Require TLS for database connections and retain client validation of the server certificate.

Description

A database that permits connections without TLS can transmit credentials, query results and application data in plaintext. Internal networks also need transport protection. PostgreSQL Flexible Server currently defaults require_secure_transport to on, so omitting the setting does not establish that encryption is disabled.

Potential impact

  • Unencrypted database traffic can be exposed or altered on the network.
  • Sensitive data may fail to meet transport-encryption requirements.

Remediation

Migrate retired Single Server deployments to supported PostgreSQL Flexible Server. Keep require_secure_transport set to on and verify application TLS connections and server certificate validation. Review minimum TLS versions and network access controls as well.

Examples

The before example is historical Single Server configuration for a retired service. Do not use it for new deployment or reuse its example password. The after excerpt shows only the transport-encryption parameter of a separately provisioned Flexible Server.

Before

hcl
resource "azurerm_postgresql_server" "example" {
  name                = "example-psqlserver"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  administrator_login          = "psqladminun"
  administrator_login_password = "H@Sh1CoR3!"

  sku_name   = "GP_Gen5_4"
  version    = "9.6"
  storage_mb = 640000

  backup_retention_days        = 7
  geo_redundant_backup_enabled = true
  auto_grow_enabled            = true

  public_network_access_enabled    = false
  ssl_enforcement_enabled          = false
  ssl_minimal_tls_version_enforced = "TLS1_2"
}

After

hcl
resource "azurerm_postgresql_flexible_server_configuration" "example" {
  name      = "require_secure_transport"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "on"
}

The after example sets require_secure_transport to on. Perform server migration and data verification separately, and verify that clients use TLS and validate the correct server certificate.

References