Language

HttpSysOptions.HttpAuthenticationHardeningLevel Property

Definition

Configures the Http.Sys authentication hardening level. Non-Legacy values instruct Http.Sys to validate the RFC 5929 TLS channel binding token (CBT) against authenticated requests and to expose the per-request CBT to the application via TryGetChannelBindingBytes(ChannelBindingKind, ReadOnlyMemory<Byte>). The default is Medium.

public Microsoft.AspNetCore.Server.HttpSys.HttpAuthenticationHardeningLevel HttpAuthenticationHardeningLevel { get; set; }
member this.HttpAuthenticationHardeningLevel : Microsoft.AspNetCore.Server.HttpSys.HttpAuthenticationHardeningLevel with get, set
Public Property HttpAuthenticationHardeningLevel As HttpAuthenticationHardeningLevel

Property Value

Remarks

Setting this to Medium or Strict both raises the hardening level and sets the HTTP_CHANNEL_BIND_SECURE_CHANNEL_TOKEN flag on the URL group's HttpServerChannelBindProperty.

Applies to