HttpSysOptions.HttpAuthenticationHardeningLevel Property
Definition
Important
Some information relates to prerelease product that may be substantially modified before it’s released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Configures the Http.Sys authentication hardening level. Non-Legacy values instruct Http.Sys to validate the RFC 5929 TLS channel binding token (CBT) against authenticated requests and to expose the per-request CBT to the application via TryGetChannelBindingBytes(ChannelBindingKind, ReadOnlyMemory<Byte>). The default is Medium.
public Microsoft.AspNetCore.Server.HttpSys.HttpAuthenticationHardeningLevel HttpAuthenticationHardeningLevel { get; set; }
member this.HttpAuthenticationHardeningLevel : Microsoft.AspNetCore.Server.HttpSys.HttpAuthenticationHardeningLevel with get, set
Public Property HttpAuthenticationHardeningLevel As HttpAuthenticationHardeningLevel
Property Value
Remarks
Setting this to Medium or Strict both raises the hardening level and sets the HTTP_CHANNEL_BIND_SECURE_CHANNEL_TOKEN flag on the URL group's HttpServerChannelBindProperty.