v11 update: TLS channel binding token access from ITlsConnectionFeature
メンテナーはふだん 1 日以内に返信
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 90/100
- issue の種類
- ドキュメント
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- csharp
調査の方向性
fundamentals/request-features.md を、131 行目の ITlsConnectionFeature エントリの後に、新しい >= aspnetcore-11.0 モニカーゾーンを使用して更新します。まず周囲のモニカー構造とリンク先の HTTP.sys の記事を確認し、その後、指定されたとおりに TryGetChannelBindingBytes とその動作を文書化します。ゾーンの対応が取れており、相対リンクが解決され、API 参照が正しくレンダリングされれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Target repository: dotnet/AspNetCore.Docs
Analyzed at commit: 4986136881f2bbf1879f10106467769df5a49932
Product source verified at: dotnet/aspnetcore @ 1fcd7ef305697a1888f3ede076010350ae9f4f8d
Source release note: TLS channel binding token access from ITlsConnectionFeature
🎯 Goal
⚠️ This issue is the deferred server-side half of #37710 (Negotiate authentication uses TLS channel binding). #37710 documented the consumer half — Negotiate on Kestrel automatically using the endpoint channel binding token — and explicitly deferred the API that exposes the token to application code. That API is the subject here: the new
ITlsConnectionFeature.TryGetChannelBindingBytesdefault interface method. See Review considerations for the three concepts that must not be conflated.
ITlsConnectionFeature is documented in fundamentals/request-features.md, but only as "an API for retrieving client certificates." The new TryGetChannelBindingBytes method — which lets any server-agnostic app retrieve an RFC 5929 channel binding token — is absent. Add a version-scoped note there, cross-linking the HTTP.sys breaking-change article (which covers the HTTP.sys implementation) and #37710 (the Negotiate consumer).
This item adds a new API (TryGetChannelBindingBytes) to an existing interface, so it's a net-new symbol, not a pure behavior change.
✅ Coverage status summary
Legend: ✅ already documented · ✏️ update needed · 🟣 could not determine
| # | Feature element from What's New | Status | Where |
|---|---|---|---|
| 1 | HTTP.sys implementation — configures HttpServerChannelBindProperty by default so the endpoint CBT is exposed through the new API |
✅ | breaking-changes/11/httpsys-channel-binding-token-enabled.md |
| 2 | Negotiate authentication consuming the endpoint CBT on Kestrel automatically | ✅ (tracked) | #37710 — the consumer half; this issue is its deferred counterpart |
| 3 | ITlsConnectionFeature.TryGetChannelBindingBytes(ChannelBindingKind, out ReadOnlyMemory<byte>) — the new server-agnostic API for retrieving a channel binding token from app code |
✏️ | 1. Update — after fundamentals/request-features.md L131 |
| 4 | Kestrel implementation of the method (via SslStream.TransportContext.GetChannelBinding) |
✏️ | Same insertion — the note should state Kestrel supports it, not only HTTP.sys |
| 5 | Intended use — Extended Protection for Authentication (EPA) / binding credentials to the TLS channel to mitigate relay attacks | ✏️ | Same insertion (one sentence of purpose) |
🔢 Version applicability
Applies to: CURRENT-ONLY
Target moniker: >= aspnetcore-11.0
Earlier versions affected: None — TryGetChannelBindingBytes is a new default interface method on net11.0. The ITlsConnectionFeature interface itself predates it and stays documented for all versions.
| Article | monikerRange |
Moniker state |
|---|---|---|
fundamentals/request-features.md |
(no front-matter monikerRange; version-agnostic article, zoned inline) |
State B — the ITlsConnectionFeature entry at L131 sits in unzoned content: the preceding :::moniker-end is at L125 and the next :::moniker range=">= aspnetcore-2.2" opens at L135, so L131 is outside any zone. Adding 11.0-only content here needs only a new >= aspnetcore-11.0 zone (open + close) — no surrounding zone to close and reopen. |
The insertion point is not inside any # [Tab](#tab/...) group, so no tab-nesting hazard applies.
📋 Coverage gap summary
A developer implementing channel-binding-aware authentication — or auditing how their app can obtain a TLS channel binding token independent of the server — looks up ITlsConnectionFeature and, in fundamentals/request-features.md, finds only "Defines an API for retrieving client certificates." The new TryGetChannelBindingBytes method, the whole point of this release note, is invisible there. The HTTP.sys breaking-change article documents the HTTP.sys server's behavior, and #37710 covers Negotiate's consumption, but the server-agnostic application API — the thing a reader of the feature interfaces page needs — is documented nowhere.
Feature announced in What's New:
ITlsConnectionFeaturenow exposesTryGetChannelBindingBytes, allowing applications to retrieve the TLS channel binding token (for example, the RFC 5929 endpoint token) for the current connection. Kestrel and HTTP.sys both implement it. Channel binding lets an authentication layer bind credentials to the underlying TLS channel, mitigating credential-relay attacks.
Product source confirms the API: ITlsConnectionFeature.cs declares the new default interface method:
public bool TryGetChannelBindingBytes(ChannelBindingKind kind, out ReadOnlyMemory<byte> channelBindingBytes)
{
channelBindingBytes = default;
return false;
}
Kestrel's implementation retrieves the token from SslStream.TransportContext.GetChannelBinding(kind). ChannelBindingKind is a dotnet/runtime type (System.Security.Authentication.ExtendedProtection); its reference below is unpinned main, since the runtime repo wasn't pinned for this analysis.
Breaking change: The HTTP.sys default-on behavior is a breaking change (documented — element 1). The API addition itself is additive (default interface method).
📁 Affected files
| Item | Path | Lines | Section |
|---|---|---|---|
| 1. | fundamentals/request-features.md |
after 131 | Feature interfaces list (ITlsConnectionFeature entry) |
Target article uids: fundamentals/request-features
📝 Proposed changes
✏️ 1. Update — request-features.md, add a >= aspnetcore-11.0 zone after the ITlsConnectionFeature entry (State B)
Applies to: >= aspnetcore-11.0
Location: Line 131 — immediately after the ITlsConnectionFeature paragraph and before the ITlsTokenBindingFeature paragraph (L133), in unzoned content (State B, new zone only).
Before (lines 131–133):
<xref:Microsoft.AspNetCore.Http.Features.ITlsConnectionFeature>: Defines an API for retrieving client certificates.
<xref:Microsoft.AspNetCore.Http.Features.ITlsTokenBindingFeature>: Defines methods for working with TLS token binding parameters.
After:
<xref:Microsoft.AspNetCore.Http.Features.ITlsConnectionFeature>: Defines an API for retrieving client certificates.
:::moniker range=">= aspnetcore-11.0"
In .NET 11 and later, `ITlsConnectionFeature` also defines `TryGetChannelBindingBytes(ChannelBindingKind, out ReadOnlyMemory<byte>)`, which retrieves an [RFC 5929](https://www.rfc-editor.org/rfc/rfc5929) TLS channel binding token—for example, the endpoint token requested with `ChannelBindingKind.Endpoint`—for the current connection. Channel binding lets an authentication layer bind credentials to the underlying TLS channel, mitigating credential-relay attacks (Extended Protection for Authentication). Kestrel implements the method over `SslStream.TransportContext.GetChannelBinding`; HTTP.sys exposes the token by default (see [HttpSys enables TLS channel binding token exposure by default](../breaking-changes/11/httpsys-channel-binding-token-enabled.md)). The method returns `false` when a token isn't available for the requested `ChannelBindingKind`.
:::moniker-end
<xref:Microsoft.AspNetCore.Http.Features.ITlsTokenBindingFeature>: Defines methods for working with TLS token binding parameters.
Rationale: The insertion point is unzoned, so a single new >= aspnetcore-11.0 zone (State B) is correct — no surrounding zone to split. Placing the note directly under the ITlsConnectionFeature entry keeps the new method next to the interface it extends. The note cross-links the HTTP.sys breaking-change article (the server-specific ✅ coverage) rather than duplicating it, and points to the RFC for the token semantics.
✅ 2. Update — TOC
No TOC change required. The edit adds a note to an existing article; no new file is created. (Worth noting for apply order: this issue proposes no toc.yml change, so there's no composition collision with #37711's TOC insertion.)
✅ Action plan
- Confirm element 1 (HTTP.sys breaking-change article) — already published.
- Apply change 1 as a State B new zone (open
>= aspnetcore-11.0, note,:::moniker-end); verify balance is net-zero (one open, one close) and the surrounding unzoned paragraphs are untouched. - Confirm the relative link
../breaking-changes/11/httpsys-channel-binding-token-enabled.mdresolves (that article has nouid). - Verify
ChannelBindingKind/ReadOnlyMemory<byte>render correctly inside the code span, and that<byte>isn't parsed as HTML (it's inside backticks).
⚠️ Review considerations
- Keep three distinct concepts separate — a reader must not conflate them:
ITlsConnectionFeature.TryGetChannelBindingBytes— the server-agnostic application API (this issue). Home:fundamentals/request-features.md.- HTTP.sys default CBT exposure — the server enabling
HttpServerChannelBindPropertyby default (breaking change,httpsys-channel-binding-token-enabled.md). This is a different, HTTP.sys-specific mechanism; it is the ✅ implementation of element 1, not a duplicate of the API note. - Negotiate consuming the endpoint CBT on Kestrel — the consumer, #37710. Distinct again from HTTP.sys
HttpSysOptionsauthentication hardening knobs such asHttpAuthenticationHardeningLevel.
- Forward-link discharge. #37710's "Review considerations" flagged this server-side/API half as deferred. This issue discharges that forward link; a reciprocal comment has been posted on #37710.
- Namespace check.
request-features.mdreferencesMicrosoft.AspNetCore.Http.Features.ITlsConnectionFeature, matching the product pathsrc/Http/Http.Features/src/ITlsConnectionFeature.cs. The xref target is correct. - 🟣 Optional Kestrel-side example. A short usage snippet could live in a Kestrel security article, but
request-features.mdis the canonical interface home and the right minimal fix. A worked EPA example is a larger, discretionary follow-up, not part of this gap.
🔗 References
- What's New section: TLS channel binding token access from ITlsConnectionFeature
- Forward-linked issue: #37710 — Negotiate authentication uses TLS channel binding (consumer half; this issue is the deferred server-side/API half).
- HTTP.sys implementation (✅):
breaking-changes/11/httpsys-channel-binding-token-enabled.md - Docset target (✏️):
fundamentals/request-features.mdL131 - Product source:
src/Http/Http.Features/src/ITlsConnectionFeature.cs— newTryGetChannelBindingBytesdefault interface method. ChannelBindingKind:System.Security.Authentication.ExtendedProtection.ChannelBindingKind—dotnet/runtime, unpinnedmain(runtime repo not pinned for this analysis).
- 主要言語
- C#
- スター
- 13.1k
- フォーク
- 24.6k
- 平均マージ
- 1日 7時間
- マージ済み PR(30日)
- 110
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
dotnet/AspNetCore.Docs のほかの issue
-
v11 update: Kestrel applies trailer header timeouts対応中かも @guardrex が 6 日前に担当しました。 オープン11.0 fundamentals/subsvc
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
dotnet/AspNetCore.Docs#37725 · リアクション 1 件 · 担当者 2 名 ·
メンテナーはふだん 1 日以内に返信
-
v11 update: Accurate rate-limiting Retry-After headers対応中かも @guardrex が 5 日前に担当しました。 オープン11.0 performance/subsvc
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
dotnet/AspNetCore.Docs#37724 · リアクション 1 件 · 担当者 2 名 ·
メンテナーはふだん 1 日以内に返信
-
v11 update: TLS handshake observability in Kestrel対応中かも @guardrex が 2 日前に担当しました。 オープン11.0 fundamentals/subsvc
難易度 2/5 1〜3時間 初心者へのやさしさ 92/100
dotnet/AspNetCore.Docs#37722 · リアクション 1 件 · 担当者 2 名 ·
メンテナーはふだん 1 日以内に返信
-
v11 update: Native OpenTelemetry tracing for ASP.NET Core対応中かも @guardrex が 2 日前に担当しました。 オープン11.0 fundamentals/subsvc
難易度 1/5 1〜3時間 初心者へのやさしさ 92/100
dotnet/AspNetCore.Docs#37721 · リアクション 1 件 · 担当者 2 名 ·
メンテナーはふだん 1 日以内に返信
-
v11 update: Auto-trust development certificates in WSL対応中かも @guardrex が 2 日前に担当しました。 オープン11.0 security/subsvc
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
dotnet/AspNetCore.Docs#37720 · リアクション 1 件 · 担当者 2 名 ·
メンテナーはふだん 1 日以内に返信
dotnet/AspNetCore.Docs の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
microsoft/fluentui-blazor#5410 ·
メンテナーはふだん 1 日以内に返信
-
Bug pulumi/pulumi
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
activescott/lessmsi#306 ·
-
Docs MSBuild
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
getsentry/sentry-dotnet#5691 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信