Description
A Function App that needs certificate-based caller authentication can receive requests without that authentication step if client certificates are not required. Mutual TLS is not necessary for every function, so establish the service’s authentication requirements first. Receiving a certificate is separate from validating it as a trusted caller identity.
Potential impact
- Certificate-based access requirements may not be met.
- Requests without a client certificate may reach the application.
- Failing to validate a forwarded certificate can admit unauthorized callers.
Remediation
When mutual TLS is required, enforce HTTPS and set client certificates to Required. For current resources, check client_certificate_enabled together with client_certificate_mode. Validate certificate trust, validity and caller permissions in the application, and test that missing or invalid certificates are rejected.
Examples
These partial examples compare client_cert_mode on the legacy AzureRM 3.x Function App. Configure required settings such as storage and HTTPS separately. Certificate setting names may differ in current resources.
Before
resource "azurerm_function_app" "example" {
name = "test-azure-functions"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
client_cert_mode = "Optional"
}
After
resource "azurerm_function_app" "example" {
name = "test-azure-functions"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
client_cert_mode = "Required"
}
The before value Optional does not require a certificate. The after value Required requires certificate submission, but the application must still validate the forwarded certificate and authorize the caller.