HttpAuthenticationHardeningLevel Enum
Definition
Important
Some information relates to prerelease product that may be substantially modified before it’s released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Specifies the Http.Sys authentication hardening level that controls how strictly HTTP authentication (Kerberos/NTLM) is validated against the underlying TLS channel.
public enum HttpAuthenticationHardeningLevel
type HttpAuthenticationHardeningLevel =
Public Enum HttpAuthenticationHardeningLevel
- Inheritance
-
HttpAuthenticationHardeningLevel
Fields
| Name | Value | Description |
|---|---|---|
| Legacy | 0 | Http.Sys does not enforce channel binding validation and does not expose the RFC 5929 TLS channel binding token to the application. This matches the pre-hardening default behavior. |
| Medium | 1 | Http.Sys validates channel binding tokens when clients supply them but tolerates their absence. The per-request TLS channel binding token is exposed to the application. |
| Strict | 2 | Http.Sys requires channel binding tokens on authenticated requests and rejects those without one. The per-request TLS channel binding token is exposed to the application. |
Remarks
Corresponds to the Win32 HTTP_AUTHENTICATION_HARDENING_LEVELShttps://learn.microsoft.com/windows/win32/api/http/ne-http-http_authentication_hardening_levels enumeration applied to the URL group's HttpServerChannelBindProperty.
When set to Medium or Strict, Http.Sys is also instructed to attach the per-request HTTP_REQUEST_CHANNEL_BIND_STATUS so the application can retrieve the RFC 5929 TLS channel binding token via TryGetChannelBindingBytes(ChannelBindingKind, ReadOnlyMemory<Byte>).