---
title: MySQL SSL connection disabled
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > Code Security > Infrastructure as Code (IaC)
  Security > IaC Security Rules > MySQL SSL connection disabled
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# MySQL SSL connection disabled

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

## Metadata{% #metadata %}

**Id:** `terraform-azure-mysql-ssl-connection-disabled` 

**Provider:** Azure

**Platform:** Terraform

**Severity:** Medium

**Category:** Encryption

#### Learn More{% #learn-more %}

- [Provider Reference](https://registry.terraform.io/providers/hashicorp/azurerm/3.6.0/docs/resources/mysql_server)

### Description{% #description %}

To ensure data transmitted between clients and the MySQL server is secure, the `ssl_enforcement_enabled` attribute in the `azurerm_mysql_server` resource should be set to `true`. If `ssl_enforcement_enabled` is set to `false`, as shown below, database connections can occur over unencrypted channels, potentially exposing sensitive information such as credentials and application data to interception and misuse.

```
resource "azurerm_mysql_server" "example" {
  ...
  ssl_enforcement_enabled = false
}
```

Enabling SSL enforcement mitigates this risk by ensuring that all clients must connect using SSL, protecting data in transit.

## Compliant Code Examples{% #compliant-code-examples %}

```terraform
resource "azurerm_resource_group" "example" {
  name     = "test-rg"
  location = "eastus"
}

resource "azurerm_mysql_flexible_server" "negative1" {
  name                = "webflux-mysql-negative"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  administrator_login    = "webflux_admin"
  administrator_password = "H@Sh1CoR3!"

  sku_name = "B_Standard_B2s"
  version  = "8.0.21"

  backup_retention_days = 7

  storage {
    size_gb           = 20
    auto_grow_enabled = true
  }
}

resource "azurerm_mysql_flexible_server_configuration" "negative1" {
  name                = "require_secure_transport"
  resource_group_name = azurerm_resource_group.example.name
  server_name         = azurerm_mysql_flexible_server.negative1.name
  value               = "ON"
}
```

## Non-Compliant Code Examples{% #non-compliant-code-examples %}

```terraform
resource "azurerm_resource_group" "example" {
  name     = "test-rg"
  location = "eastus"
}

resource "azurerm_mysql_flexible_server" "positive1" {
  name                = "webflux-mysql-positive"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  administrator_login    = "webflux_admin"
  administrator_password = "H@Sh1CoR3!"

  sku_name = "B_Standard_B2s"
  version  = "8.0.21"

  backup_retention_days = 7

  storage {
    size_gb           = 20
    auto_grow_enabled = true
  }
}

resource "azurerm_mysql_flexible_server_configuration" "positive1" {
  name                = "require_secure_transport"
  resource_group_name = azurerm_resource_group.example.name
  server_name         = azurerm_mysql_flexible_server.positive1.name
  value               = "OFF"
}
```
