Description
Client certificates can authenticate callers of internal APIs or B2B integrations. They are not required for every app, but a service designed to require them loses that protection if certificates are not requested or validated. The application must validate the certificates forwarded by App Service and decide whether they are trusted.
Potential impact
Incomplete certificate requirements or trust validation can let callers access sensitive functions that were intended to require a trusted certificate.
Remediation
Enable client certificates where needed, require HTTPS, and use Required mode. Review excluded paths and validate certificate chains, validity periods, and allowed identities in the app. For HTTP/2 or TLS 1.3, avoid certificate modes and exclusion paths that require TLS renegotiation.
Examples
These examples use the legacy AzureRM 3.x azurerm_app_service resource. Current resources use client_certificate_enabled and client_certificate_mode; certificate-validation code is separate.
Before
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
}
After
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
client_cert_enabled = true
}
The revision enables client certificates. This setting alone does not validate the issuing authority or the caller’s permissions.