Skip to content

Harden ClientCertificateMode config validation #69707

Agent suggestions

Public preview

Description

@hoyosjs

Currently ClientCertificateMode can be set via config, but when it's parsed via ParseClientCertificateMode we perform no validation on the value. The bad value path sets the default to null which then falls to no-mutual-tls. This means typos become the laxest policy possible. We should revisit this stance.

Options:

  • Select a higher default in case of misconfiguration.
  • Warn the user via log.
  • Fail the request altogether.

Activity

  1. added
    area-networkingIncludes servers, yarp, json patch, bedrock, websockets, http client factory, and http abstractions
    on Oct 7, 2026
  2. github-actions commented on Oct 7, 2026

    @github-actions
    Contributor

    Triage Summary

    Area: area-networking (Kestrel HTTPS ClientCertificateMode configuration parsing)
    Type: Feature (requests a change to how invalid configuration values are handled)

    Potential Duplicates

    • None found

    Generated by Issue Triage Agent for dotnet/aspnetcore for #69707 · copilot · auto · 26.3 AIC · ⌖ 8.88 AIC · ⊞ 30.5K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-networkingIncludes servers, yarp, json patch, bedrock, websockets, http client factory, and http abstractions

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions