Language

HttpAuthenticationHardeningLevel Enum

Definition

Specifies the Http.Sys authentication hardening level that controls how strictly HTTP authentication (Kerberos/NTLM) is validated against the underlying TLS channel.

public enum HttpAuthenticationHardeningLevel
type HttpAuthenticationHardeningLevel = 
Public Enum HttpAuthenticationHardeningLevel
Inheritance
HttpAuthenticationHardeningLevel

Fields

Name Value Description
Legacy 0

Http.Sys does not enforce channel binding validation and does not expose the RFC 5929 TLS channel binding token to the application. This matches the pre-hardening default behavior.

Medium 1

Http.Sys validates channel binding tokens when clients supply them but tolerates their absence. The per-request TLS channel binding token is exposed to the application.

Strict 2

Http.Sys requires channel binding tokens on authenticated requests and rejects those without one. The per-request TLS channel binding token is exposed to the application.

Remarks

Corresponds to the Win32 HTTP_AUTHENTICATION_HARDENING_LEVELShttps://learn.microsoft.com/windows/win32/api/http/ne-http-http_authentication_hardening_levels enumeration applied to the URL group's HttpServerChannelBindProperty.

When set to Medium or Strict, Http.Sys is also instructed to attach the per-request HTTP_REQUEST_CHANNEL_BIND_STATUS so the application can retrieve the RFC 5929 TLS channel binding token via TryGetChannelBindingBytes(ChannelBindingKind, ReadOnlyMemory<Byte>).

Applies to