Currently ClientCertificateMode can be set via config, but when it's parsed via ParseClientCertificateMode we perform no validation on the value. The bad value path sets the default to null which then falls to no-mutual-tls. This means typos become the laxest policy possible. We should revisit this stance.
Options:
- Select a higher default in case of misconfiguration.
- Warn the user via log.
- Fail the request altogether.
Currently
ClientCertificateModecan be set via config, but when it's parsed viaParseClientCertificateModewe perform no validation on the value. The bad value path sets the default to null which then falls to no-mutual-tls. This means typos become the laxest policy possible. We should revisit this stance.Options: