Review Web App client certificate settings

For services that need client certificates, configure both certificate requirements and application validation.

Description

Client certificates can provide additional authentication for management APIs or B2B services used by a limited set of clients. They are not mandatory for every web app; choose them according to the service's authentication requirements.

App Service forwards client certificates to the application without validating their trust. Do not authorize a request merely because a certificate was presented. The application must validate the issuer and trust chain, validity period, revocation status, and authorized client identity.

Potential impact

  • Missing certificate requirements or validation on a protected path can allow unauthorized clients' requests to be processed.
  • Accepting expired or revoked certificates, or lacking a rotation procedure, can cause unauthorized access or connection failures.

Remediation

On a supported App Service plan, enable clientCertEnabled and set clientCertMode to Required when a certificate is mandatory. Review exclusions and protocol compatibility, and use HTTPS. Validate certificates in the application, authorize only required actions, and test valid, missing, and invalid certificate requests. Maintain issuance, replacement, and revocation procedures.

Examples

These are site-property excerpts. Supply the actual app name, region, a certificate-capable App Service plan, and other inputs separately. Certificate mode and application validation code are omitted.

Before

bicep
resource webSite 'Microsoft.Web/sites@2020-12-01' = {
  name: 'webSite'
  location: 'location1'
  tags: {}
  properties: {
    enabled: true
  }
}

This does not specify the client certificate feature. Review the service's required authentication method and current settings.

After

bicep
resource webSite 'Microsoft.Web/sites@2020-12-01' = {
  name: 'webSite'
  location: 'location1'
  tags: {}
  properties: {
    enabled: true
    clientCertEnabled: true
  }
}

This enables the client certificate feature. Mode and exclusion paths determine whether certificates are mandatory; configure application logic to validate the forwarded certificate.

References