Language

ITlsConnectionFeature.TryGetChannelBindingBytes Method

Definition

Attempts to retrieve the RFC 5929 TLS channel binding token (CBT) bytes for the requested kind from the current connection.

public virtual bool TryGetChannelBindingBytes(System.Security.Authentication.ExtendedProtection.ChannelBindingKind kind, out ReadOnlyMemory<byte> channelBindingToken);
abstract member TryGetChannelBindingBytes : System.Security.Authentication.ExtendedProtection.ChannelBindingKind * ReadOnlyMemory -> bool
override this.TryGetChannelBindingBytes : System.Security.Authentication.ExtendedProtection.ChannelBindingKind * ReadOnlyMemory -> bool
Public Overridable Function TryGetChannelBindingBytes (kind As ChannelBindingKind, ByRef channelBindingToken As ReadOnlyMemory(Of Byte)) As Boolean

Parameters

kind
ChannelBindingKind

The kind of channel binding to retrieve.

channelBindingToken
ReadOnlyMemory<Byte>

When this method returns true, contains the channel binding token bytes; otherwise, an empty ReadOnlyMemory<T>.

Returns

true if the requested channel binding is available; false otherwise (for example: the connection is not TLS, the requested kind is not supported by the server, or channel binding is not enabled in server configuration).

Remarks

Channel binding tokens let in-channel authentication protocols (such as Kerberos or NTLM negotiated over HTTPS) bind themselves cryptographically to the underlying TLS channel, mitigating authentication relay attacks. See https://datatracker.ietf.org/doc/html/rfc5929 for the specification and Microsoft's "Extended Protection for Authentication" documentation for the Windows usage model.

Applies to