Review App Service client certificate requirements

Apply certificate requirements and validation to paths that need certificate-based caller authentication.

Description

Client certificates can authenticate callers of internal APIs or B2B integrations. They are not required for every app, but a service designed to require them loses that protection if certificates are not requested or validated. The application must validate the certificates forwarded by App Service and decide whether they are trusted.

Potential impact

Incomplete certificate requirements or trust validation can let callers access sensitive functions that were intended to require a trusted certificate.

Remediation

Enable client certificates where needed, require HTTPS, and use Required mode. Review excluded paths and validate certificate chains, validity periods, and allowed identities in the app. For HTTP/2 or TLS 1.3, avoid certificate modes and exclusion paths that require TLS renegotiation.

Examples

These examples use the legacy AzureRM 3.x azurerm_app_service resource. Current resources use client_certificate_enabled and client_certificate_mode; certificate-validation code is separate.

Before

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id
}

After

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  client_cert_enabled = true
}

The revision enables client certificates. This setting alone does not validate the issuing authority or the caller’s permissions.

References