Skip to content

[Investigate] Determine if disabling certificate revocation list checking is bad practice in the Android Broker scenariosΒ #1642

@trwalke

Description

@trwalke

Investigate weather or not there will be an potential security issue if we enable broker support on MSAL.NET with the broker signature verification not checking against certificate revocation lists.

We have a new build warning in MSAL with the new android broker implementation:
Warning IA5352: Do Not Change X509ChainPolicy. RevocationMode to NoCheck

Coming from here

Should speak with the MSAL android team to determine how they handle certificate revocation.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions