ITlsConnectionFeature.TryGetChannelBindingBytes Method
Definition
Important
Some information relates to prerelease product that may be substantially modified before it’s released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Attempts to retrieve the RFC 5929 TLS channel binding token (CBT) bytes for the
requested kind from the current connection.
public virtual bool TryGetChannelBindingBytes(System.Security.Authentication.ExtendedProtection.ChannelBindingKind kind, out ReadOnlyMemory<byte> channelBindingToken);
abstract member TryGetChannelBindingBytes : System.Security.Authentication.ExtendedProtection.ChannelBindingKind * ReadOnlyMemory -> bool
override this.TryGetChannelBindingBytes : System.Security.Authentication.ExtendedProtection.ChannelBindingKind * ReadOnlyMemory -> bool
Public Overridable Function TryGetChannelBindingBytes (kind As ChannelBindingKind, ByRef channelBindingToken As ReadOnlyMemory(Of Byte)) As Boolean
Parameters
- kind
- ChannelBindingKind
The kind of channel binding to retrieve.
- channelBindingToken
- ReadOnlyMemory<Byte>
When this method returns true, contains the channel binding token
bytes; otherwise, an empty ReadOnlyMemory<T>.
Returns
true if the requested channel binding is available;
false otherwise (for example: the connection is not TLS,
the requested kind is not supported by the server, or
channel binding is not enabled in server configuration).
Remarks
Channel binding tokens let in-channel authentication protocols (such as Kerberos or NTLM negotiated over HTTPS) bind themselves cryptographically to the underlying TLS channel, mitigating authentication relay attacks. See https://datatracker.ietf.org/doc/html/rfc5929 for the specification and Microsoft's "Extended Protection for Authentication" documentation for the Windows usage model.