Skip to content

Fix: Enforce minimum TLS 1.2 for Azure Storage Account - #2207

Open
Tanmaykaturi wants to merge 20 commits into
aquasecurity:masterfrom
Tanmaykaturi:master
Open

Fix: Enforce minimum TLS 1.2 for Azure Storage Account#2207
Tanmaykaturi wants to merge 20 commits into
aquasecurity:masterfrom
Tanmaykaturi:master

Conversation

@Tanmaykaturi

Copy link
Copy Markdown

⏺ Summary

Adds an explicit min_tls_version = "TLS1_2" setting to the azurerm_storage_account.storage_accounts resource in _examples/971/modules/azure/storage-account/module.tf.

Problem

The azurerm_storage_account resource did not specify a minimum TLS version, allowing the storage account to accept connections over TLS 1.0 or TLS 1.1. Both protocols are deprecated and are known to be vulnerable to attacks such as POODLE and
BEAST. This was flagged by tfsec as storage-use-secure-tls-policy.

Solution

Explicitly set min_tls_version = "TLS1_2" on the resource to enforce TLS 1.2 as the minimum accepted protocol version.

resource "azurerm_storage_account" "storage_accounts" {

  • name = var.name
  • name = var.name
  • min_tls_version = "TLS1_2"
    }

Impact

  • Enforces TLS 1.2 as the minimum protocol version for all client connections to this storage account.
  • Brings the module into alignment with the Azure Security Benchmark and Microsoft's recommended best practices.
  • No functional impact is expected for clients already connecting over TLS 1.2 or later. Clients still relying on TLS 1.0/1.1 will need to upgrade their connection configuration.

appuser and others added 2 commits July 30, 2026 05:57
…e-tls-policy-1-UxldWMIb1i

fix: semgrep-storage-use-secure-tls-policy
@CLAassistant

CLAassistant commented Jul 30, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ Tanmaykaturi
❌ appuser


appuser seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

appuser and others added 18 commits July 30, 2026 08:24
…icy-8-XkhPBw3qrx

fix: semgrep-aws-iam-admin-policy
…dfront-distribution-tls-v-1-GRUnyfFnVl

fix: semgrep-aws-insecure-cloudfront-distribution-tls-version
…vices-logging-1-ED9FjAhb53

fix: semgrep-storage-queue-services-logging
…ancer-tls-version-9-xWIr0DQ9Hw

fix: semgrep-insecure-load-balancer-tls-version
…cket-5-tU9hXysE8M

fix: semgrep-s3-public-read-bucket
…ancer-tls-version-9-soB0c7ug5y

fix: semgrep-insecure-load-balancer-tls-version
…ate-8-i755dXKiHh

fix: semgrep-import-text-template
…late-8-YNgYcRQYmr

fix: semgrep-import-text-template
…e-unencrypted-49-ybUqr7KddI

fix: semgrep-aws-dynamodb-table-unencrypted
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants