Description
The SMB channel cipher policy limits the ciphers available for file-share connections. If your organization requires AES-256-GCM, review whether other ciphers are allowed. AES-128-CCM and AES-128-GCM are also supported encryption algorithms; allowing them does not by itself mean traffic is plaintext or the encryption is broken.
Potential impact
- Allowing ciphers outside an organization’s requirements can violate its encryption policy.
- Restricting access to an unsupported cipher can prevent clients from connecting to the file share.
Remediation
Set share_properties.smb.channel_encryption_type = ["AES-256-GCM"] if AES-256-GCM is required. Clients must support SMB 3.1.1 and this cipher, and their allowed cipher configuration must agree. Check enforcement of encryption in transit separately, and test mounts and normal file operations.
Examples
These excerpts compare allowed SMB ciphers. Retain the actual account name, Region and replication settings. The examples use a Standard StorageV2 account that supports share_properties.
Before
resource "azurerm_storage_account" "file_storage" {
name = "appstorage002"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
share_properties {
smb {
channel_encryption_type = ["AES-128-CCM", "AES-128-GCM"]
}
}
}
AES-128-CCM and AES-128-GCM are allowed. This is a different cipher policy from an AES-256-GCM-only requirement, not an example of absent encryption.
After
resource "azurerm_storage_account" "file_storage" {
name = "protectedstore02"
resource_group_name = "testRG"
location = "northeurope"
account_tier = "Standard"
account_replication_type = "LRS"
share_properties {
smb {
channel_encryption_type = ["AES-256-GCM"]
}
}
}
Only AES-256-GCM is allowed. Check the version and cipher configuration of supported clients, such as Windows 11 or Windows Server 2022.