Skip to content

Format net_ssl_io_cert_validation in TlsSession reject path - #135351

Merged
MihaZupan merged 1 commit into
dotnet:mainfrom
caraioniurie47:issue-135349
Oct 7, 2026
Merged

MihaZupan merged 1 commit into
dotnet:mainfrom
caraioniurie47:issue-135349

Conversation

@caraioniurie47

Copy link
Copy Markdown
Contributor

TlsSession.SetRemoteCertificateValidationResult created its AuthenticationException from SR.net_ssl_io_cert_validation without SR.Format at two sites (the _isHandshakeComplete branch and the _resumeAfterCertValidation branch), so a rejection that faulted the session there produced the message "The remote certificate is invalid according to the validation procedure: {0}".

This change formats the resource with the caller's SslPolicyErrors at both sites, as SslStream does:

SslStream.IO.cs:710

                return ExceptionDispatchInfo.SetCurrentStackTrace(new AuthenticationException(SR.Format(SR.net_ssl_io_cert_validation, sslPolicyErrors), null));

ServerSession_ExternalValidation_RejectsClientCert_ServerFaultsPostHoc (TLS 1.2 and TLS 1.3 rows) now keeps the server-side AuthenticationException and asserts that its message contains RemoteCertificateChainErrors and does not contain {0}. Both rows fail on the old code with Assert.Contains() Failure and pass with the fix.

On Linux with OpenSSL 3.0.13 both rows reach the first site (the _isHandshakeComplete branch); the second site (the _resumeAfterCertValidation branch) is not reached there.

On Windows 11 x64 both rows also fail on the old code and pass with the fix; which site they reach there was not checked. Not run on macOS.

The System.Net.Security functional tests passed on Linux x64 with the change (OuterLoop tests not run). On Windows 11 x64 they passed except SslStreamTlsResumeTests.DifferentEncryptionPolicy_NoResume, which failed once in the full run (Assert.Equal() Failure, expected True, actual False) and passed in three separate runs of that test alone.

Resolves #135349

Note

AI-generated, written at my direction and reviewed by me before posting.
Source read at dotnet/runtime 6f1d933. Tests ran on Ubuntu 24.04.4 LTS x64 with OpenSSL 3.0.13, against a ./build.sh clr+libs -rc Release build of that commit plus this change, with dotnet build src/libraries/System.Net.Security/tests/FunctionalTests /t:Test. The old-code run put back TlsSession.cs from that commit and rebuilt src/libraries/System.Net.Security/src before running the test.
Windows: Windows 11 Pro for Workstations x64 (10.0.26300), against a build.cmd clr+libs -rc checked build of dotnet/runtime d148189 plus this change (TlsSession.cs and TlsSessionTests.cs are the same blobs there as at 6f1d933), with dotnet.cmd build /t:Test in src/libraries/System.Net.Security/tests/FunctionalTests; the old-code run put back TlsSession.cs from d148189 and rebuilt src/libraries/System.Net.Security/src.

TlsSession.SetRemoteCertificateValidationResult built its
AuthenticationException from SR.net_ssl_io_cert_validation without
SR.Format, so the message ended in a literal "{0}". Format it with the
caller's SslPolicyErrors verdict, as SslStream does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dotnet-policy-service dotnet-policy-service Bot added the community-contribution Indicates that the PR has been added by a community member label Oct 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 4 pipeline(s).
12 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@wfurt wfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the contribution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Net.Security community-contribution Indicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TlsSession.SetRemoteCertificateValidationResult rejection message ends in a literal {0}

3 participants