Skip to content

Support certificate validation TLS alerts for Linux - #115996

Merged
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms
Apr 17, 2026
Merged

Support certificate validation TLS alerts for Linux#115996
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms

Conversation

@rzikm

@rzikmrzikm commented May 26, 2025

Copy link
Copy Markdown
Member

Contributes to #18837.

Summary

On Linux, SslStream previously closed the transport without sending a TLS alert when certificate validation failed. This PR makes SslStream send appropriate TLS alerts (e.g. bad_certificate, unknown_ca, certificate_expired, certificate_required) by moving certificate validation inline into the OpenSSL handshake via SSL_CTX_set_cert_verify_cb.

How it works

Instead of validating the peer certificate after the handshake completes (post-handshake), the validation now runs inside OpenSSL's certificate verification callback during the handshake itself. This allows OpenSSL to send the appropriate TLS alert to the peer when validation fails, since the handshake is still in progress.

The CertVerifyCallback (registered on the SSL_CTX) extracts the certificate chain from the X509_STORE_CTX, then calls the existing managed VerifyRemoteCertificate logic — including the user's RemoteCertificateValidationCallback if one is registered. If validation fails, the callback maps the failure reason to an X509_V_ERR_* status code, which OpenSSL translates into the corresponding TLS alert.

Connection info during the callback

Because the callback fires mid-handshake, connection properties like SslProtocol and CipherAlgorithm would normally not be available yet. To preserve backward compatibility with user callbacks that access these properties, _connectionInfo is populated before invoking the user callback. On TLS 1.2, SSL_get_current_cipher() returns NULL at this point (the session cipher is set at ChangeCipherSpec), so the native code falls back to SSL_get_pending_cipher() which is available once ServerHello has been processed.

Propagating exceptions from validation callback

The exception that would normally be thrown from the cert validation (either AuthenticationException, or whatever user code throws) is caught and stored in SafeSslHandle before returning back to OpenSSL code, and when the control flow returns from SSL_do_handshake, the exception gets rethrown.

Client certificates and ClientCertificateRequired

OpenSSL only invokes the cert verify callback when the peer actually sends a certificate. When a server sets ClientCertificateRequired = true but the client sends no certificate, the callback never fires. Two cases are handled:

  • No user callback registered:SSL_VERIFY_FAIL_IF_NO_PEER_CERT is set alongside SSL_VERIFY_PEER, so OpenSSL itself rejects the handshake and sends the certificate_required (TLS 1.3) or handshake_failure (TLS 1.2) alert.
  • User callback registered: Only SSL_VERIFY_PEER is set. The handshake succeeds, and managed CompleteHandshake code detects that _remoteCertificate is still null, then calls VerifyRemoteCertificate which invokes the user's callback with SslPolicyErrors.RemoteCertificateNotAvailable. This preserves the existing behavior where applications can accept connections without a client certificate via the callback, unfortunately, no TLS alert is sent in this case.

Resumed sessions

On resumed sessions, OpenSSL skips the cert verify callback since the certificate was already validated in the original handshake. CompleteHandshake detects this (_remoteCertificate is null) and retrieves the peer certificate from the SSL handle via GetRemoteCertificate and valites it post-handshake, previous behavior is preserved (no TLS alert is sent if revalidation fails, but this is not expected to happen often in practice).

@rzikmrzikm changed the title Implement certificate verification callback and related enhancements[WIP] Support certificate validation for TLS alerts for LinuxMay 26, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@rzikmrzikm changed the title [WIP] Support certificate validation for TLS alerts for Linux[WIP] Support certificate validation TLS alerts for LinuxJul 1, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Draft Pull Request was automatically closed for 30 days of inactivity. Please let us know if you'd like to reopen it.

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Aug 31, 2025
@rzikmrzikm reopened this Mar 2, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 1 comment.

@liveansliveans left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

CopilotAI review requested due to automatic review settings April 14, 2026 13:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 2 comments.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

CopilotAI review requested due to automatic review settings April 15, 2026 15:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.c Outdated
CopilotAI review requested due to automatic review settings April 16, 2026 14:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

@rzikm
rzikm merged commit 6a04342 into dotnet:mainApr 17, 2026
106 of 112 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 17, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@rzikm@wfurt@bartonjs@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Support certificate validation TLS alerts for Linux by rzikm · Pull Request #115996 · dotnet/runtime · GitHub
Skip to content

Support certificate validation TLS alerts for Linux - #115996

Merged
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms
Apr 17, 2026
Merged

Support certificate validation TLS alerts for Linux#115996
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms

Conversation

@rzikm

@rzikmrzikm commented May 26, 2025

Copy link
Copy Markdown
Member

Contributes to #18837.

Summary

On Linux, SslStream previously closed the transport without sending a TLS alert when certificate validation failed. This PR makes SslStream send appropriate TLS alerts (e.g. bad_certificate, unknown_ca, certificate_expired, certificate_required) by moving certificate validation inline into the OpenSSL handshake via SSL_CTX_set_cert_verify_cb.

How it works

Instead of validating the peer certificate after the handshake completes (post-handshake), the validation now runs inside OpenSSL's certificate verification callback during the handshake itself. This allows OpenSSL to send the appropriate TLS alert to the peer when validation fails, since the handshake is still in progress.

The CertVerifyCallback (registered on the SSL_CTX) extracts the certificate chain from the X509_STORE_CTX, then calls the existing managed VerifyRemoteCertificate logic — including the user's RemoteCertificateValidationCallback if one is registered. If validation fails, the callback maps the failure reason to an X509_V_ERR_* status code, which OpenSSL translates into the corresponding TLS alert.

Connection info during the callback

Because the callback fires mid-handshake, connection properties like SslProtocol and CipherAlgorithm would normally not be available yet. To preserve backward compatibility with user callbacks that access these properties, _connectionInfo is populated before invoking the user callback. On TLS 1.2, SSL_get_current_cipher() returns NULL at this point (the session cipher is set at ChangeCipherSpec), so the native code falls back to SSL_get_pending_cipher() which is available once ServerHello has been processed.

Propagating exceptions from validation callback

The exception that would normally be thrown from the cert validation (either AuthenticationException, or whatever user code throws) is caught and stored in SafeSslHandle before returning back to OpenSSL code, and when the control flow returns from SSL_do_handshake, the exception gets rethrown.

Client certificates and ClientCertificateRequired

OpenSSL only invokes the cert verify callback when the peer actually sends a certificate. When a server sets ClientCertificateRequired = true but the client sends no certificate, the callback never fires. Two cases are handled:

  • No user callback registered:SSL_VERIFY_FAIL_IF_NO_PEER_CERT is set alongside SSL_VERIFY_PEER, so OpenSSL itself rejects the handshake and sends the certificate_required (TLS 1.3) or handshake_failure (TLS 1.2) alert.
  • User callback registered: Only SSL_VERIFY_PEER is set. The handshake succeeds, and managed CompleteHandshake code detects that _remoteCertificate is still null, then calls VerifyRemoteCertificate which invokes the user's callback with SslPolicyErrors.RemoteCertificateNotAvailable. This preserves the existing behavior where applications can accept connections without a client certificate via the callback, unfortunately, no TLS alert is sent in this case.

Resumed sessions

On resumed sessions, OpenSSL skips the cert verify callback since the certificate was already validated in the original handshake. CompleteHandshake detects this (_remoteCertificate is null) and retrieves the peer certificate from the SSL handle via GetRemoteCertificate and valites it post-handshake, previous behavior is preserved (no TLS alert is sent if revalidation fails, but this is not expected to happen often in practice).

@rzikmrzikm changed the title Implement certificate verification callback and related enhancements[WIP] Support certificate validation for TLS alerts for LinuxMay 26, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@rzikmrzikm changed the title [WIP] Support certificate validation for TLS alerts for Linux[WIP] Support certificate validation TLS alerts for LinuxJul 1, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Draft Pull Request was automatically closed for 30 days of inactivity. Please let us know if you'd like to reopen it.

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Aug 31, 2025
@rzikmrzikm reopened this Mar 2, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 1 comment.

@liveansliveans left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

CopilotAI review requested due to automatic review settings April 14, 2026 13:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 2 comments.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

CopilotAI review requested due to automatic review settings April 15, 2026 15:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.c Outdated
CopilotAI review requested due to automatic review settings April 16, 2026 14:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

@rzikm
rzikm merged commit 6a04342 into dotnet:mainApr 17, 2026
106 of 112 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 17, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@rzikm@wfurt@bartonjs@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Support certificate validation TLS alerts for Linux by rzikm · Pull Request #115996 · dotnet/runtime · GitHub
Skip to content

Support certificate validation TLS alerts for Linux - #115996

Merged
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms
Apr 17, 2026
Merged

Support certificate validation TLS alerts for Linux#115996
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms

Conversation

@rzikm

@rzikmrzikm commented May 26, 2025

Copy link
Copy Markdown
Member

Contributes to #18837.

Summary

On Linux, SslStream previously closed the transport without sending a TLS alert when certificate validation failed. This PR makes SslStream send appropriate TLS alerts (e.g. bad_certificate, unknown_ca, certificate_expired, certificate_required) by moving certificate validation inline into the OpenSSL handshake via SSL_CTX_set_cert_verify_cb.

How it works

Instead of validating the peer certificate after the handshake completes (post-handshake), the validation now runs inside OpenSSL's certificate verification callback during the handshake itself. This allows OpenSSL to send the appropriate TLS alert to the peer when validation fails, since the handshake is still in progress.

The CertVerifyCallback (registered on the SSL_CTX) extracts the certificate chain from the X509_STORE_CTX, then calls the existing managed VerifyRemoteCertificate logic — including the user's RemoteCertificateValidationCallback if one is registered. If validation fails, the callback maps the failure reason to an X509_V_ERR_* status code, which OpenSSL translates into the corresponding TLS alert.

Connection info during the callback

Because the callback fires mid-handshake, connection properties like SslProtocol and CipherAlgorithm would normally not be available yet. To preserve backward compatibility with user callbacks that access these properties, _connectionInfo is populated before invoking the user callback. On TLS 1.2, SSL_get_current_cipher() returns NULL at this point (the session cipher is set at ChangeCipherSpec), so the native code falls back to SSL_get_pending_cipher() which is available once ServerHello has been processed.

Propagating exceptions from validation callback

The exception that would normally be thrown from the cert validation (either AuthenticationException, or whatever user code throws) is caught and stored in SafeSslHandle before returning back to OpenSSL code, and when the control flow returns from SSL_do_handshake, the exception gets rethrown.

Client certificates and ClientCertificateRequired

OpenSSL only invokes the cert verify callback when the peer actually sends a certificate. When a server sets ClientCertificateRequired = true but the client sends no certificate, the callback never fires. Two cases are handled:

  • No user callback registered:SSL_VERIFY_FAIL_IF_NO_PEER_CERT is set alongside SSL_VERIFY_PEER, so OpenSSL itself rejects the handshake and sends the certificate_required (TLS 1.3) or handshake_failure (TLS 1.2) alert.
  • User callback registered: Only SSL_VERIFY_PEER is set. The handshake succeeds, and managed CompleteHandshake code detects that _remoteCertificate is still null, then calls VerifyRemoteCertificate which invokes the user's callback with SslPolicyErrors.RemoteCertificateNotAvailable. This preserves the existing behavior where applications can accept connections without a client certificate via the callback, unfortunately, no TLS alert is sent in this case.

Resumed sessions

On resumed sessions, OpenSSL skips the cert verify callback since the certificate was already validated in the original handshake. CompleteHandshake detects this (_remoteCertificate is null) and retrieves the peer certificate from the SSL handle via GetRemoteCertificate and valites it post-handshake, previous behavior is preserved (no TLS alert is sent if revalidation fails, but this is not expected to happen often in practice).

@rzikmrzikm changed the title Implement certificate verification callback and related enhancements[WIP] Support certificate validation for TLS alerts for LinuxMay 26, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@rzikmrzikm changed the title [WIP] Support certificate validation for TLS alerts for Linux[WIP] Support certificate validation TLS alerts for LinuxJul 1, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Draft Pull Request was automatically closed for 30 days of inactivity. Please let us know if you'd like to reopen it.

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Aug 31, 2025
@rzikmrzikm reopened this Mar 2, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 1 comment.

@liveansliveans left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

CopilotAI review requested due to automatic review settings April 14, 2026 13:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 2 comments.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

CopilotAI review requested due to automatic review settings April 15, 2026 15:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.c Outdated
CopilotAI review requested due to automatic review settings April 16, 2026 14:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

@rzikm
rzikm merged commit 6a04342 into dotnet:mainApr 17, 2026
106 of 112 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 17, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@rzikm@wfurt@bartonjs@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Support certificate validation TLS alerts for Linux by rzikm · Pull Request #115996 · dotnet/runtime · GitHub
Skip to content

Support certificate validation TLS alerts for Linux - #115996

Merged
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms
Apr 17, 2026
Merged

Support certificate validation TLS alerts for Linux#115996
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms

Conversation

@rzikm

@rzikmrzikm commented May 26, 2025

Copy link
Copy Markdown
Member

Contributes to #18837.

Summary

On Linux, SslStream previously closed the transport without sending a TLS alert when certificate validation failed. This PR makes SslStream send appropriate TLS alerts (e.g. bad_certificate, unknown_ca, certificate_expired, certificate_required) by moving certificate validation inline into the OpenSSL handshake via SSL_CTX_set_cert_verify_cb.

How it works

Instead of validating the peer certificate after the handshake completes (post-handshake), the validation now runs inside OpenSSL's certificate verification callback during the handshake itself. This allows OpenSSL to send the appropriate TLS alert to the peer when validation fails, since the handshake is still in progress.

The CertVerifyCallback (registered on the SSL_CTX) extracts the certificate chain from the X509_STORE_CTX, then calls the existing managed VerifyRemoteCertificate logic — including the user's RemoteCertificateValidationCallback if one is registered. If validation fails, the callback maps the failure reason to an X509_V_ERR_* status code, which OpenSSL translates into the corresponding TLS alert.

Connection info during the callback

Because the callback fires mid-handshake, connection properties like SslProtocol and CipherAlgorithm would normally not be available yet. To preserve backward compatibility with user callbacks that access these properties, _connectionInfo is populated before invoking the user callback. On TLS 1.2, SSL_get_current_cipher() returns NULL at this point (the session cipher is set at ChangeCipherSpec), so the native code falls back to SSL_get_pending_cipher() which is available once ServerHello has been processed.

Propagating exceptions from validation callback

The exception that would normally be thrown from the cert validation (either AuthenticationException, or whatever user code throws) is caught and stored in SafeSslHandle before returning back to OpenSSL code, and when the control flow returns from SSL_do_handshake, the exception gets rethrown.

Client certificates and ClientCertificateRequired

OpenSSL only invokes the cert verify callback when the peer actually sends a certificate. When a server sets ClientCertificateRequired = true but the client sends no certificate, the callback never fires. Two cases are handled:

  • No user callback registered:SSL_VERIFY_FAIL_IF_NO_PEER_CERT is set alongside SSL_VERIFY_PEER, so OpenSSL itself rejects the handshake and sends the certificate_required (TLS 1.3) or handshake_failure (TLS 1.2) alert.
  • User callback registered: Only SSL_VERIFY_PEER is set. The handshake succeeds, and managed CompleteHandshake code detects that _remoteCertificate is still null, then calls VerifyRemoteCertificate which invokes the user's callback with SslPolicyErrors.RemoteCertificateNotAvailable. This preserves the existing behavior where applications can accept connections without a client certificate via the callback, unfortunately, no TLS alert is sent in this case.

Resumed sessions

On resumed sessions, OpenSSL skips the cert verify callback since the certificate was already validated in the original handshake. CompleteHandshake detects this (_remoteCertificate is null) and retrieves the peer certificate from the SSL handle via GetRemoteCertificate and valites it post-handshake, previous behavior is preserved (no TLS alert is sent if revalidation fails, but this is not expected to happen often in practice).

@rzikmrzikm changed the title Implement certificate verification callback and related enhancements[WIP] Support certificate validation for TLS alerts for LinuxMay 26, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@rzikmrzikm changed the title [WIP] Support certificate validation for TLS alerts for Linux[WIP] Support certificate validation TLS alerts for LinuxJul 1, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Draft Pull Request was automatically closed for 30 days of inactivity. Please let us know if you'd like to reopen it.

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Aug 31, 2025
@rzikmrzikm reopened this Mar 2, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 1 comment.

@liveansliveans left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

CopilotAI review requested due to automatic review settings April 14, 2026 13:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 2 comments.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

CopilotAI review requested due to automatic review settings April 15, 2026 15:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.c Outdated
CopilotAI review requested due to automatic review settings April 16, 2026 14:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

@rzikm
rzikm merged commit 6a04342 into dotnet:mainApr 17, 2026
106 of 112 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 17, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@rzikm@wfurt@bartonjs@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Support certificate validation TLS alerts for Linux by rzikm · Pull Request #115996 · dotnet/runtime · GitHub
Skip to content

Support certificate validation TLS alerts for Linux - #115996

Merged
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms
Apr 17, 2026
Merged

Support certificate validation TLS alerts for Linux#115996
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms

Conversation

@rzikm

@rzikmrzikm commented May 26, 2025

Copy link
Copy Markdown
Member

Contributes to #18837.

Summary

On Linux, SslStream previously closed the transport without sending a TLS alert when certificate validation failed. This PR makes SslStream send appropriate TLS alerts (e.g. bad_certificate, unknown_ca, certificate_expired, certificate_required) by moving certificate validation inline into the OpenSSL handshake via SSL_CTX_set_cert_verify_cb.

How it works

Instead of validating the peer certificate after the handshake completes (post-handshake), the validation now runs inside OpenSSL's certificate verification callback during the handshake itself. This allows OpenSSL to send the appropriate TLS alert to the peer when validation fails, since the handshake is still in progress.

The CertVerifyCallback (registered on the SSL_CTX) extracts the certificate chain from the X509_STORE_CTX, then calls the existing managed VerifyRemoteCertificate logic — including the user's RemoteCertificateValidationCallback if one is registered. If validation fails, the callback maps the failure reason to an X509_V_ERR_* status code, which OpenSSL translates into the corresponding TLS alert.

Connection info during the callback

Because the callback fires mid-handshake, connection properties like SslProtocol and CipherAlgorithm would normally not be available yet. To preserve backward compatibility with user callbacks that access these properties, _connectionInfo is populated before invoking the user callback. On TLS 1.2, SSL_get_current_cipher() returns NULL at this point (the session cipher is set at ChangeCipherSpec), so the native code falls back to SSL_get_pending_cipher() which is available once ServerHello has been processed.

Propagating exceptions from validation callback

The exception that would normally be thrown from the cert validation (either AuthenticationException, or whatever user code throws) is caught and stored in SafeSslHandle before returning back to OpenSSL code, and when the control flow returns from SSL_do_handshake, the exception gets rethrown.

Client certificates and ClientCertificateRequired

OpenSSL only invokes the cert verify callback when the peer actually sends a certificate. When a server sets ClientCertificateRequired = true but the client sends no certificate, the callback never fires. Two cases are handled:

  • No user callback registered:SSL_VERIFY_FAIL_IF_NO_PEER_CERT is set alongside SSL_VERIFY_PEER, so OpenSSL itself rejects the handshake and sends the certificate_required (TLS 1.3) or handshake_failure (TLS 1.2) alert.
  • User callback registered: Only SSL_VERIFY_PEER is set. The handshake succeeds, and managed CompleteHandshake code detects that _remoteCertificate is still null, then calls VerifyRemoteCertificate which invokes the user's callback with SslPolicyErrors.RemoteCertificateNotAvailable. This preserves the existing behavior where applications can accept connections without a client certificate via the callback, unfortunately, no TLS alert is sent in this case.

Resumed sessions

On resumed sessions, OpenSSL skips the cert verify callback since the certificate was already validated in the original handshake. CompleteHandshake detects this (_remoteCertificate is null) and retrieves the peer certificate from the SSL handle via GetRemoteCertificate and valites it post-handshake, previous behavior is preserved (no TLS alert is sent if revalidation fails, but this is not expected to happen often in practice).

@rzikmrzikm changed the title Implement certificate verification callback and related enhancements[WIP] Support certificate validation for TLS alerts for LinuxMay 26, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@rzikmrzikm changed the title [WIP] Support certificate validation for TLS alerts for Linux[WIP] Support certificate validation TLS alerts for LinuxJul 1, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Draft Pull Request was automatically closed for 30 days of inactivity. Please let us know if you'd like to reopen it.

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Aug 31, 2025
@rzikmrzikm reopened this Mar 2, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 1 comment.

@liveansliveans left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

CopilotAI review requested due to automatic review settings April 14, 2026 13:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 2 comments.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

CopilotAI review requested due to automatic review settings April 15, 2026 15:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.c Outdated
CopilotAI review requested due to automatic review settings April 16, 2026 14:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

@rzikm
rzikm merged commit 6a04342 into dotnet:mainApr 17, 2026
106 of 112 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 17, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@rzikm@wfurt@bartonjs@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Support certificate validation TLS alerts for Linux by rzikm · Pull Request #115996 · dotnet/runtime · GitHub
Skip to content

Support certificate validation TLS alerts for Linux - #115996

Merged
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms
Apr 17, 2026
Merged

Support certificate validation TLS alerts for Linux#115996
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms

Conversation

@rzikm

@rzikmrzikm commented May 26, 2025

Copy link
Copy Markdown
Member

Contributes to #18837.

Summary

On Linux, SslStream previously closed the transport without sending a TLS alert when certificate validation failed. This PR makes SslStream send appropriate TLS alerts (e.g. bad_certificate, unknown_ca, certificate_expired, certificate_required) by moving certificate validation inline into the OpenSSL handshake via SSL_CTX_set_cert_verify_cb.

How it works

Instead of validating the peer certificate after the handshake completes (post-handshake), the validation now runs inside OpenSSL's certificate verification callback during the handshake itself. This allows OpenSSL to send the appropriate TLS alert to the peer when validation fails, since the handshake is still in progress.

The CertVerifyCallback (registered on the SSL_CTX) extracts the certificate chain from the X509_STORE_CTX, then calls the existing managed VerifyRemoteCertificate logic — including the user's RemoteCertificateValidationCallback if one is registered. If validation fails, the callback maps the failure reason to an X509_V_ERR_* status code, which OpenSSL translates into the corresponding TLS alert.

Connection info during the callback

Because the callback fires mid-handshake, connection properties like SslProtocol and CipherAlgorithm would normally not be available yet. To preserve backward compatibility with user callbacks that access these properties, _connectionInfo is populated before invoking the user callback. On TLS 1.2, SSL_get_current_cipher() returns NULL at this point (the session cipher is set at ChangeCipherSpec), so the native code falls back to SSL_get_pending_cipher() which is available once ServerHello has been processed.

Propagating exceptions from validation callback

The exception that would normally be thrown from the cert validation (either AuthenticationException, or whatever user code throws) is caught and stored in SafeSslHandle before returning back to OpenSSL code, and when the control flow returns from SSL_do_handshake, the exception gets rethrown.

Client certificates and ClientCertificateRequired

OpenSSL only invokes the cert verify callback when the peer actually sends a certificate. When a server sets ClientCertificateRequired = true but the client sends no certificate, the callback never fires. Two cases are handled:

  • No user callback registered:SSL_VERIFY_FAIL_IF_NO_PEER_CERT is set alongside SSL_VERIFY_PEER, so OpenSSL itself rejects the handshake and sends the certificate_required (TLS 1.3) or handshake_failure (TLS 1.2) alert.
  • User callback registered: Only SSL_VERIFY_PEER is set. The handshake succeeds, and managed CompleteHandshake code detects that _remoteCertificate is still null, then calls VerifyRemoteCertificate which invokes the user's callback with SslPolicyErrors.RemoteCertificateNotAvailable. This preserves the existing behavior where applications can accept connections without a client certificate via the callback, unfortunately, no TLS alert is sent in this case.

Resumed sessions

On resumed sessions, OpenSSL skips the cert verify callback since the certificate was already validated in the original handshake. CompleteHandshake detects this (_remoteCertificate is null) and retrieves the peer certificate from the SSL handle via GetRemoteCertificate and valites it post-handshake, previous behavior is preserved (no TLS alert is sent if revalidation fails, but this is not expected to happen often in practice).

@rzikmrzikm changed the title Implement certificate verification callback and related enhancements[WIP] Support certificate validation for TLS alerts for LinuxMay 26, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@rzikmrzikm changed the title [WIP] Support certificate validation for TLS alerts for Linux[WIP] Support certificate validation TLS alerts for LinuxJul 1, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Draft Pull Request was automatically closed for 30 days of inactivity. Please let us know if you'd like to reopen it.

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Aug 31, 2025
@rzikmrzikm reopened this Mar 2, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 1 comment.

@liveansliveans left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

CopilotAI review requested due to automatic review settings April 14, 2026 13:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 2 comments.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

CopilotAI review requested due to automatic review settings April 15, 2026 15:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.c Outdated
CopilotAI review requested due to automatic review settings April 16, 2026 14:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

@rzikm
rzikm merged commit 6a04342 into dotnet:mainApr 17, 2026
106 of 112 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 17, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@rzikm@wfurt@bartonjs@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Support certificate validation TLS alerts for Linux by rzikm · Pull Request #115996 · dotnet/runtime · GitHub
Skip to content

Support certificate validation TLS alerts for Linux - #115996

Merged
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms
Apr 17, 2026
Merged

Support certificate validation TLS alerts for Linux#115996
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms

Conversation

@rzikm

@rzikmrzikm commented May 26, 2025

Copy link
Copy Markdown
Member

Contributes to #18837.

Summary

On Linux, SslStream previously closed the transport without sending a TLS alert when certificate validation failed. This PR makes SslStream send appropriate TLS alerts (e.g. bad_certificate, unknown_ca, certificate_expired, certificate_required) by moving certificate validation inline into the OpenSSL handshake via SSL_CTX_set_cert_verify_cb.

How it works

Instead of validating the peer certificate after the handshake completes (post-handshake), the validation now runs inside OpenSSL's certificate verification callback during the handshake itself. This allows OpenSSL to send the appropriate TLS alert to the peer when validation fails, since the handshake is still in progress.

The CertVerifyCallback (registered on the SSL_CTX) extracts the certificate chain from the X509_STORE_CTX, then calls the existing managed VerifyRemoteCertificate logic — including the user's RemoteCertificateValidationCallback if one is registered. If validation fails, the callback maps the failure reason to an X509_V_ERR_* status code, which OpenSSL translates into the corresponding TLS alert.

Connection info during the callback

Because the callback fires mid-handshake, connection properties like SslProtocol and CipherAlgorithm would normally not be available yet. To preserve backward compatibility with user callbacks that access these properties, _connectionInfo is populated before invoking the user callback. On TLS 1.2, SSL_get_current_cipher() returns NULL at this point (the session cipher is set at ChangeCipherSpec), so the native code falls back to SSL_get_pending_cipher() which is available once ServerHello has been processed.

Propagating exceptions from validation callback

The exception that would normally be thrown from the cert validation (either AuthenticationException, or whatever user code throws) is caught and stored in SafeSslHandle before returning back to OpenSSL code, and when the control flow returns from SSL_do_handshake, the exception gets rethrown.

Client certificates and ClientCertificateRequired

OpenSSL only invokes the cert verify callback when the peer actually sends a certificate. When a server sets ClientCertificateRequired = true but the client sends no certificate, the callback never fires. Two cases are handled:

  • No user callback registered:SSL_VERIFY_FAIL_IF_NO_PEER_CERT is set alongside SSL_VERIFY_PEER, so OpenSSL itself rejects the handshake and sends the certificate_required (TLS 1.3) or handshake_failure (TLS 1.2) alert.
  • User callback registered: Only SSL_VERIFY_PEER is set. The handshake succeeds, and managed CompleteHandshake code detects that _remoteCertificate is still null, then calls VerifyRemoteCertificate which invokes the user's callback with SslPolicyErrors.RemoteCertificateNotAvailable. This preserves the existing behavior where applications can accept connections without a client certificate via the callback, unfortunately, no TLS alert is sent in this case.

Resumed sessions

On resumed sessions, OpenSSL skips the cert verify callback since the certificate was already validated in the original handshake. CompleteHandshake detects this (_remoteCertificate is null) and retrieves the peer certificate from the SSL handle via GetRemoteCertificate and valites it post-handshake, previous behavior is preserved (no TLS alert is sent if revalidation fails, but this is not expected to happen often in practice).

@rzikmrzikm changed the title Implement certificate verification callback and related enhancements[WIP] Support certificate validation for TLS alerts for LinuxMay 26, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@rzikmrzikm changed the title [WIP] Support certificate validation for TLS alerts for Linux[WIP] Support certificate validation TLS alerts for LinuxJul 1, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Draft Pull Request was automatically closed for 30 days of inactivity. Please let us know if you'd like to reopen it.

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Aug 31, 2025
@rzikmrzikm reopened this Mar 2, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 1 comment.

@liveansliveans left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

CopilotAI review requested due to automatic review settings April 14, 2026 13:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 2 comments.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

CopilotAI review requested due to automatic review settings April 15, 2026 15:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.c Outdated
CopilotAI review requested due to automatic review settings April 16, 2026 14:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

@rzikm
rzikm merged commit 6a04342 into dotnet:mainApr 17, 2026
106 of 112 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 17, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@rzikm@wfurt@bartonjs@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Support certificate validation TLS alerts for Linux by rzikm · Pull Request #115996 · dotnet/runtime · GitHub
Skip to content

Support certificate validation TLS alerts for Linux - #115996

Merged
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms
Apr 17, 2026
Merged

Support certificate validation TLS alerts for Linux#115996
rzikm merged 37 commits into
dotnet:mainfrom
rzikm:18837-Supports-TLS-alerts-for-cert-validation-for-non-Windows-platforms

Conversation

@rzikm

@rzikmrzikm commented May 26, 2025

Copy link
Copy Markdown
Member

Contributes to #18837.

Summary

On Linux, SslStream previously closed the transport without sending a TLS alert when certificate validation failed. This PR makes SslStream send appropriate TLS alerts (e.g. bad_certificate, unknown_ca, certificate_expired, certificate_required) by moving certificate validation inline into the OpenSSL handshake via SSL_CTX_set_cert_verify_cb.

How it works

Instead of validating the peer certificate after the handshake completes (post-handshake), the validation now runs inside OpenSSL's certificate verification callback during the handshake itself. This allows OpenSSL to send the appropriate TLS alert to the peer when validation fails, since the handshake is still in progress.

The CertVerifyCallback (registered on the SSL_CTX) extracts the certificate chain from the X509_STORE_CTX, then calls the existing managed VerifyRemoteCertificate logic — including the user's RemoteCertificateValidationCallback if one is registered. If validation fails, the callback maps the failure reason to an X509_V_ERR_* status code, which OpenSSL translates into the corresponding TLS alert.

Connection info during the callback

Because the callback fires mid-handshake, connection properties like SslProtocol and CipherAlgorithm would normally not be available yet. To preserve backward compatibility with user callbacks that access these properties, _connectionInfo is populated before invoking the user callback. On TLS 1.2, SSL_get_current_cipher() returns NULL at this point (the session cipher is set at ChangeCipherSpec), so the native code falls back to SSL_get_pending_cipher() which is available once ServerHello has been processed.

Propagating exceptions from validation callback

The exception that would normally be thrown from the cert validation (either AuthenticationException, or whatever user code throws) is caught and stored in SafeSslHandle before returning back to OpenSSL code, and when the control flow returns from SSL_do_handshake, the exception gets rethrown.

Client certificates and ClientCertificateRequired

OpenSSL only invokes the cert verify callback when the peer actually sends a certificate. When a server sets ClientCertificateRequired = true but the client sends no certificate, the callback never fires. Two cases are handled:

  • No user callback registered:SSL_VERIFY_FAIL_IF_NO_PEER_CERT is set alongside SSL_VERIFY_PEER, so OpenSSL itself rejects the handshake and sends the certificate_required (TLS 1.3) or handshake_failure (TLS 1.2) alert.
  • User callback registered: Only SSL_VERIFY_PEER is set. The handshake succeeds, and managed CompleteHandshake code detects that _remoteCertificate is still null, then calls VerifyRemoteCertificate which invokes the user's callback with SslPolicyErrors.RemoteCertificateNotAvailable. This preserves the existing behavior where applications can accept connections without a client certificate via the callback, unfortunately, no TLS alert is sent in this case.

Resumed sessions

On resumed sessions, OpenSSL skips the cert verify callback since the certificate was already validated in the original handshake. CompleteHandshake detects this (_remoteCertificate is null) and retrieves the peer certificate from the SSL handle via GetRemoteCertificate and valites it post-handshake, previous behavior is preserved (no TLS alert is sent if revalidation fails, but this is not expected to happen often in practice).

@rzikmrzikm changed the title Implement certificate verification callback and related enhancements[WIP] Support certificate validation for TLS alerts for LinuxMay 26, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@rzikmrzikm changed the title [WIP] Support certificate validation for TLS alerts for Linux[WIP] Support certificate validation TLS alerts for LinuxJul 1, 2025
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Draft Pull Request was automatically closed for 30 days of inactivity. Please let us know if you'd like to reopen it.

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Aug 31, 2025
@rzikmrzikm reopened this Mar 2, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 1 comment.

@liveansliveans left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

CopilotAI review requested due to automatic review settings April 14, 2026 13:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 20 out of 21 changed files in this pull request and generated 2 comments.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

CopilotAI review requested due to automatic review settings April 15, 2026 15:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_ssl.c Outdated
CopilotAI review requested due to automatic review settings April 16, 2026 14:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 21 out of 22 changed files in this pull request and generated 2 comments.

@rzikm
rzikm merged commit 6a04342 into dotnet:mainApr 17, 2026
106 of 112 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 17, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@rzikm@wfurt@bartonjs@liveans