Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Minimum TLS version "Default" meaning query. #122367

Closed
stadion-ianjones opened this issue May 9, 2024 · 3 comments
Closed

Minimum TLS version "Default" meaning query. #122367

stadion-ianjones opened this issue May 9, 2024 · 3 comments

Comments

@stadion-ianjones
Copy link

Minimum TLS version "Default" query.

I see a note was added to the docs under section "Check whether your application is already compliant"
"With your cache open in the portal, select Advanced in the resource menu. If the Minimum TLS version for your cache instance is set to Default, your Minimum TLS version is set to TLS 1.2. TLS 1.2 is the default value that is assigned to your cache instance when no explicit value is chosen."

However I still get an Azure Advisor recommendation "Support for TLS versions 1.0 and 1.1 is retiring on October 31, 2024."
With a recommended action
"Remove the use of TLS 1.0 and 1.1 from Azure Cache for Redis."
That links back to this document.

Does it matter when the Azure Cache for Redis was created, for what "Default" means?
Or does the detection mechanism in the Azure Advisor need updating?

Seems conflicting information on if an action is required to explicitly set the minimum version to 1.2, or if "default" already has this set?


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

@TPavanBalaji
Copy link

@stadion-ianjones
Thanks for your feedback! We will investigate and update as appropriate.

@Naveenommi-MSFT
Copy link
Contributor

Hello @stadion-ianjones
The Azure Advisor recommendation you received is correct. Although the default value for the Minimum TLS version for Azure Cache for Redis is TLS 1.2, it is still recommended to explicitly set the minimum version to 1.2 to ensure that your cache is compliant with the latest security standards.

The note you mentioned in the documentation is correct as well. If the Minimum TLS version for your cache instance is set to Default, your Minimum TLS version is set to TLS 1.2. However, it is still recommended to explicitly set the minimum version to 1.2 to ensure that your cache is compliant with the latest security standards.

Therefore, to comply with the latest security standards, it is recommended to explicitly set the minimum version to 1.2, even if your cache was created with the default value of TLS 1.2.

@Naveenommi-MSFT
Copy link
Contributor

@stadion-ianjones
We are going to close this thread, if there are any further questions regarding the documentation, please tag me in your reply and we will be happy to continue the conversation.

#Please-close

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants