-
Notifications
You must be signed in to change notification settings - Fork 12.7k
Consider support for SNI certificate selection from X509Store #21300
Copy link
Copy link
Open
Labels
affected-fewThis issue impacts only small number of customersThis issue impacts only small number of customersarea-networkingIncludes servers, yarp, json patch, bedrock, websockets, http client factory, and http abstractionsIncludes servers, yarp, json patch, bedrock, websockets, http client factory, and http abstractionsenhancementThis issue represents an ask for new feature or an enhancement to an existing oneThis issue represents an ask for new feature or an enhancement to an existing onefeature-yarpThis issue is related to work on yarpThis issue is related to work on yarpseverity-minorThis label is used by an internal toolThis label is used by an internal tool
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
affected-fewThis issue impacts only small number of customersThis issue impacts only small number of customersarea-networkingIncludes servers, yarp, json patch, bedrock, websockets, http client factory, and http abstractionsIncludes servers, yarp, json patch, bedrock, websockets, http client factory, and http abstractionsenhancementThis issue represents an ask for new feature or an enhancement to an existing oneThis issue represents an ask for new feature or an enhancement to an existing onefeature-yarpThis issue is related to work on yarpThis issue is related to work on yarpseverity-minorThis label is used by an internal toolThis label is used by an internal tool
This is something that came up in YARP (dotnet/yarp#86).
We should consider an "automatic" certificate selection option in Kestrel to select certificates from
X509Storebased on the server name in the SNI store.The design proposed by @davidni in the YARP issue is something like this:
nullif none match. Cert selection is always O(1) w.r.t number of bound host names, including for wildcard matches.With "reasonable" and "best" defined as:
Definition of reasonable cert: Similar to Kestrel's existing logic:
1.3.6.1.5.5.7.3.1Enhanced Key Usage oid when the extension is presentX509Certificate2.Verify()to also check for revocation, whereasX509CertificateStore.Find(... validOnly: true)(used in Kestrel's defaults) does not check revocation.Definition of best cert: The most recently-issued certificate that is reasonable.