説明
Azure Storageで安全な転送を必須にしないと、HTTP要求を受け付ける場合があります。クライアントがHTTPを使うと、転送中のデータや資格情報が露出するおそれがあります。
想定される影響
暗号化されていない要求を傍受できる第三者に、データやSASトークンを読み取られるおそれがあります。
対処方法
https_traffic_only_enabled = trueを設定し、クライアントもHTTPSを使うように変更してください。ファイル共有では、SMB接続も暗号化されていることを確認してください。
例
以下は現在のAzureRMの安全な転送オプションを設定する抜粋例です。
変更前
hcl
resource "azurerm_storage_account" "example" {
name = "example1"
resource_group_name = data.azurerm_resource_group.example.name
location = data.azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
https_traffic_only_enabled = false
}
変更後
hcl
resource "azurerm_storage_account" "example" {
name = "example"
resource_group_name = data.azurerm_resource_group.example.name
location = data.azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
https_traffic_only_enabled = true
}