Review Function App client certificate requirements

Require and validate client certificates for functions that need mutual TLS authentication.

Description

A Function App that needs certificate-based caller authentication can receive requests without that authentication step if client certificates are not required. Mutual TLS is not necessary for every function, so establish the service’s authentication requirements first. Receiving a certificate is separate from validating it as a trusted caller identity.

Potential impact

  • Certificate-based access requirements may not be met.
  • Requests without a client certificate may reach the application.
  • Failing to validate a forwarded certificate can admit unauthorized callers.

Remediation

When mutual TLS is required, enforce HTTPS and set client certificates to Required. For current resources, check client_certificate_enabled together with client_certificate_mode. Validate certificate trust, validity and caller permissions in the application, and test that missing or invalid certificates are rejected.

Examples

These partial examples compare client_cert_mode on the legacy AzureRM 3.x Function App. Configure required settings such as storage and HTTPS separately. Certificate setting names may differ in current resources.

Before

hcl
resource "azurerm_function_app" "example" {
  name                = "test-azure-functions"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  client_cert_mode = "Optional"
}

After

hcl
resource "azurerm_function_app" "example" {
  name                = "test-azure-functions"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  client_cert_mode = "Required"
}

The before value Optional does not require a certificate. The after value Required requires certificate submission, but the application must still validate the forwarded certificate and authorize the caller.

References