Skip to content

Commit 1c0dc71

Browse files
committed
Add Database Mail configuration for TLS 1.3
- Added Database Mail bullet point to secure-by-default configurations - Documented default settings (Encrypt=Optional, TrustServerCertificate=True) - Documented TLS 1.3 enforced settings (Encrypt=Strict, TrustServerCertificate=False) - Added note about Managed Instances using TLS 1.3 by default
1 parent 0e2d7fd commit 1c0dc71

File tree

1 file changed

+2
-0
lines changed
  • docs/relational-databases/security/networking

1 file changed

+2
-0
lines changed

docs/relational-databases/security/networking/tls-1-3.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -95,6 +95,8 @@ SQL Server 2025 introduces secure-by-default configurations for several features
9595

9696
- **Replication**: (Transactional, Snapshot, Merge) Uses Microsoft OLE DB Driver for SQL Server version 19 with `Encrypt=Mandatory` and requires valid certificates with `TrustServerCertificate=False`.
9797

98+
- **Database Mail**: The default settings are `Encrypt=Optional` and `TrustServerCertificate=True`. When TLS 1.3 is enforced, these values change to `Encrypt=Strict` and `TrustServerCertificate=False`. By default, Azure SQL Managed Instance uses the TLS 1.3 protocol.
99+
98100
- **PolyBase**: Uses ODBC Driver for SQL Server version 18 with `Encrypt=Yes` (`Mandatory`). PolyBase allows `TrustServerCertificate=True` for self-signed scenarios.
99101

100102
- **SQL VSS Writer**: When connecting to a SQL Server 2025 instance with `Encryption=Strict`, SQL VSS Writer will use TLS 1.3 and TDS 8.0 for the non-Virtual Device Interface (VDI) part of that connection.

0 commit comments

Comments
 (0)