Azure Cloud Witness: Azure Advisor Security Warning for HTTP Storage Connections?

We’ve taken to deploying a Cloud Witness for almost all of our Windows Server based clusters whether Hyper-V, Storage Spaces Direct (S2D), or Scale-Out File Server.

When logging on to the Azure Portal this morning we were prompted to check out a number of different areas by the Azure Advisor.

 image

What caught our eye was a red bang High Impact recommendation in the Security Advisor.

image

Security Advisor: 3 Recommendations

After clicking in we saw:

image

High: Secure transfer to storage accounts should be enabled

We click on the link and we see three cloud witness storage resources that have been around for quite a long time.

image

Cloud Witness Storage Resources

Before we pulled the trigger on enabling the HTTPS connections we reached out to the Storage Team and asked whether the change would impact any of our cluster’s Cloud Witness setups.

They confirmed that the entire Cloud Witness setup was secured behind HTTPS and was done so from the beginning.

So, off we went:

image

image

It took a few minutes for things to clear up and finally let us know that the Security Advisor was happy.

image

Remediation successful

The Advisor still showed the warning for the storage accounts after the above. So, it looks as though it may take a while before things refresh fully within the system.

Conclusion

The moral of the story: It’s okay to flip the bit on Storage HTTPS connections without being concerned about losing the witness at the cluster level.

Philip Elder
Microsoft High Availability MVP
MPECS Inc.
www.s2d.rocks !
Our Web Site
PowerShell and CMD Guides

Leave a comment

Your email address will not be published.