Azure Redis で暗号化されていない接続を許可

非 TLS ポートを無効にし、アプリケーションが TLS 接続を使うように構成してください。

説明

Azure Cache for Redis の非 TLS ポートを有効にすると、そのポートに到達できるクライアントは TLS なしの接続を利用できます。Redis には機密性のあるセッション、トークン、キャッシュデータが保存される場合があり、平文の接続ではデータや認証情報が漏えいするおそれがあります。

想定される影響

  • 暗号化されていない接続のキャッシュデータや認証情報が、ネットワーク上で漏えいする場合があります。
  • 通信経路を観測・改変できる攻撃者に、セッションやトークンを盗まれるおそれがあります。

対処方法

現在のプロバイダーでは non_ssl_port_enabled = false、AzureRM 3.117.1 では enable_non_ssl_port = false で非 TLS ポートを無効にしてください。アプリケーションと運用ツールで TLS 接続とサーバー証明書検証を使い、最小 TLS バージョンとネットワークアクセスも確認してください。

例

以下は AzureRM 3.117.1 の enable_non_ssl_port 属性を使う例です。現在のプロバイダーでは non_ssl_port_enabled が対応する属性です。参照リソースは別途構成してください。

変更前

hcl
resource "azurerm_redis_cache" "example" {
  name                = "example-cache"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  capacity            = 2
  family              = "C"
  sku_name            = "Standard"
  enable_non_ssl_port = true
  minimum_tls_version = "1.2"

  redis_configuration {
  }
}

変更後

hcl
resource "azurerm_redis_cache" "example" {
  name                = "example-cache"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  capacity            = 2
  family              = "C"
  sku_name            = "Standard"
  enable_non_ssl_port = false
  minimum_tls_version = "1.2"

  redis_configuration {
  }
}

変更後は非 TLS ポートを無効にします。認証とアクセス権限を維持しながら、クライアントも TLS ポートを使うように変更してください。

参考資料