Redis Caching & Messaging (Pub/Sub, Streams) · Lección

Cifrado en tránsito con TLS

Proteja el tráfico de Redis frente a escuchas no autorizadas habilitando TLS, configurando certificados y conectándose de forma segura desde los clientes.

Lección 4 de 413 pasos

Cifrado en tránsito con TLS es una lección gratuita de Redis Caching & Messaging (Pub/Sub, Streams) en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Redis Caching & Messaging (Pub/Sub, Streams), y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Redis Caching & Messaging (Pub/Sub, Streams) incluye 4 lecciones en total.

Partes de esta lección aún no han sido traducidas y se muestran en inglés.

Why Encrypt in Transit?

By default Redis speaks plaintext over the network. Anyone able to sniff the wire can read your commands, including AUTH passwords and cached data. TLS encrypts the connection so traffic stays confidential and tamper-evident.

TLS Building Blocks

TLS uses certificates:

  • A server certificate proves the server's identity
  • A private key the server keeps secret
  • A CA certificate clients use to verify the server

Generating Certificates

For testing, the Redis source ships a helper script, or you can use openssl to create a CA and a server cert/key pair.

openssl req -x509 -newkey rsa:4096 -keyout server.key -out server.crt -days 365 -nodes

Enabling TLS on the Server

Configure the TLS port and certificate paths. Setting port 0 disables the plaintext port so only TLS is accepted.

tls-port 6379
port 0
tls-cert-file server.crt
tls-key-file server.key
tls-ca-cert-file ca.crt

Mutual TLS

For stronger security, require clients to present their own certificate (mTLS). The server then authenticates the client in addition to encrypting traffic.

tls-auth-clients yes

Connecting with redis-cli

redis-cli supports TLS with the --tls flag plus the CA and, for mTLS, the client cert and key.

redis-cli --tls --cacert ca.crt -h myhost -p 6379

Connecting from Code

Client libraries accept TLS settings: enable TLS, point to the CA, and (for mTLS) the client certificate and key.

client = redis.Redis(host='myhost', port=6379, ssl=True, ssl_ca_certs='ca.crt')

Replication and Cluster over TLS

Inter-node traffic should be encrypted too. Enable tls-replication yes and tls-cluster yes so replicas and cluster bus connections also use TLS.

tls-replication yes
tls-cluster yes

Protocol and Cipher Hardening

Restrict allowed protocols and ciphers to modern, strong options to avoid downgrade attacks.

tls-protocols "TLSv1.2 TLSv1.3"

TLS Is Not Everything

TLS protects data in transit, not at rest, and does not replace authentication. Keep using requirepass/ACLs and bind to trusted interfaces; TLS is one layer of defense in depth.

Cost and Trade-offs

TLS adds CPU overhead for the handshake and encryption. It is usually negligible with persistent connections and connection pooling, but worth measuring under load.

Quick Check

Test your understanding of Redis TLS.

Recap

You enabled TLS on Redis: generated certificates, configured the TLS port and key/cert files, optionally required client certs for mTLS, secured replication and cluster traffic, and connected from CLI and code. Remember TLS is one layer; pair it with authentication and network isolation.

Gratis para empezar

Aprende Redis Caching & Messaging (Pub/Sub, Streams) con un tutor de IA — gratis

Escribe y ejecuta código real en tu navegador, obtén ayuda instantánea de un tutor de IA disponible 24/7 y continúa donde lo dejaste en la web o en la aplicación.

Cursos
12
Lecciones
48

Preguntas frecuentes

¿La lección «Cifrado en tránsito con TLS» es gratis?

Sí — el texto completo de «Cifrado en tránsito con TLS» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Redis Caching & Messaging (Pub/Sub, Streams), actualiza a CoddyKit PRO. El curso de Redis Caching & Messaging (Pub/Sub, Streams) incluye 4 lecciones en total.

¿Qué aprenderé en «Cifrado en tránsito con TLS»?

Proteja el tráfico de Redis frente a escuchas no autorizadas habilitando TLS, configurando certificados y conectándose de forma segura desde los clientes. Practicas Redis Caching & Messaging (Pub/Sub, Streams) con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.

¿Necesito experiencia previa para empezar Redis Caching & Messaging (Pub/Sub, Streams)?

No se requiere experiencia previa. Redis Caching & Messaging (Pub/Sub, Streams) en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.

¿Cuánto tiempo toma la lección «Cifrado en tránsito con TLS»?

La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.

¿Puedo escribir y ejecutar código en esta lección de Redis Caching & Messaging (Pub/Sub, Streams)?

Sí. Cada lección de Redis Caching & Messaging (Pub/Sub, Streams) incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.

Todas las lecciones de este curso

  1. Autenticación y autorización
  2. Seguridad de red para Redis
  3. Buenas prácticas operativas
  4. Cifrado en tránsito con TLS
← Volver a Redis Caching & Messaging (Pub/Sub, Streams)