Description
Client certificates can provide additional authentication for management APIs or B2B services used by a limited set of clients. They are not mandatory for every web app; choose them according to the service's authentication requirements.
App Service forwards client certificates to the application without validating their trust. Do not authorize a request merely because a certificate was presented. The application must validate the issuer and trust chain, validity period, revocation status, and authorized client identity.
Potential impact
- Missing certificate requirements or validation on a protected path can allow unauthorized clients' requests to be processed.
- Accepting expired or revoked certificates, or lacking a rotation procedure, can cause unauthorized access or connection failures.
Remediation
On a supported App Service plan, enable clientCertEnabled and set clientCertMode to Required when a certificate is mandatory. Review exclusions and protocol compatibility, and use HTTPS. Validate certificates in the application, authorize only required actions, and test valid, missing, and invalid certificate requests. Maintain issuance, replacement, and revocation procedures.
Examples
These are site-property excerpts. Supply the actual app name, region, a certificate-capable App Service plan, and other inputs separately. Certificate mode and application validation code are omitted.
Before
resource webSite 'Microsoft.Web/sites@2020-12-01' = {
name: 'webSite'
location: 'location1'
tags: {}
properties: {
enabled: true
}
}
This does not specify the client certificate feature. Review the service's required authentication method and current settings.
After
resource webSite 'Microsoft.Web/sites@2020-12-01' = {
name: 'webSite'
location: 'location1'
tags: {}
properties: {
enabled: true
clientCertEnabled: true
}
}
This enables the client certificate feature. Mode and exclusion paths determine whether certificates are mandatory; configure application logic to validate the forwarded certificate.