One case of the theory failed during the TLS handshake on linux-x64 Debug with the Mono interpreter, on Ubuntu.2604.Amd64.Open (test run net11.0-linux-Debug-x64-Mono_Interpreter_Debug, work item System.Net.Security.Tests). Of 5081 tests, 1 failed. The certificate validation callback rejected the remote certificate. The PR doesn't touch System.Net.Security or Mono; it changes only a WASI-specific path in Dns.cs.
System.Net.Security.Tests.SslStreamTls13NetworkConformanceTests.ZeroByteWrite_OtherDataReceivedSuccessfully(mode: AsyncMemory) [FAIL]
System.Security.Authentication.AuthenticationException : The remote certificate was rejected by the provided RemoteCertificateValidationCallback.
Stack Trace:
/_/src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.cs(700,0): at System.Net.Security.SslStream.CreateCertificateValidationException(SslAuthenticationOptions options, SslPolicyErrors sslPolicyErrors, X509ChainStatusFlags chainStatus)
/_/src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.cs(691,0): at System.Net.Security.SslStream.CompleteHandshake(SslAuthenticationOptions sslAuthenticationOptions)
/_/src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.cs(420,0): at System.Net.Security.SslStream.<ForceAuthenticationAsync>d__159`1[[System.AsyncReadWriteAdapter, System.Net.Security, Version=11.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a]].MoveNext()
...
/_/src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.cs(552,0): at System.Net.Security.SslStream.<ReceiveHandshakeFrameAsync>d__160`1[[System.AsyncReadWriteAdapter, System.Net.Security, Version=11.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a]].MoveNext()
{
"ErrorMessage": [
"System.Net.Security.Tests.SslStream",
"System.Security.Authentication.AuthenticationException : The remote certificate was rejected by the provided RemoteCertificateValidationCallback."
],
"ErrorPattern": "",
"BuildRetry": false,
"ExcludeConsoleLog": false
}
Build Information
Build: https://dev.azure.com/dnceng-public/public/_build/results?buildId=1619940
Build error leg or test failing: build_linux_x64_Debug_Mono_Interpreter_LibrariesTests-System.Net.Security.Tests
Pull request: #135033
KBE authoring guidance (ci-failure-scan)
Error Detailsis for readers. Paste the full exception, stack trace, or build error excerpt so the failure is understandable without opening the raw log.Error Message.ErrorMessageis a case-sensitive ordinalString.Containssubstring copied verbatim from the failing log.BuildRetrytotrueonly for a clear infrastructure retry case.ExcludeConsoleLogdisables Helix console-log scanning.One case of the theory failed during the TLS handshake on linux-x64 Debug with the Mono interpreter, on Ubuntu.2604.Amd64.Open (test run
net11.0-linux-Debug-x64-Mono_Interpreter_Debug, work itemSystem.Net.Security.Tests). Of 5081 tests, 1 failed. The certificate validation callback rejected the remote certificate. The PR doesn't touch System.Net.Security or Mono; it changes only a WASI-specific path inDns.cs.#135041 reports the same exception in the same leg configuration (Mono interpreter, linux-x64 Debug) for a different test,
SslStreamTls12NetworkConformanceTests.ReadAsync_ContinuesOnCurrentSynchronizationContextIfDesired. The two failures may share a root cause. #135041'sErrorMessageincludes its own test name, so it doesn't match this failure.Error Details
Error Message
{ "ErrorMessage": [ "System.Net.Security.Tests.SslStream", "System.Security.Authentication.AuthenticationException : The remote certificate was rejected by the provided RemoteCertificateValidationCallback." ], "ErrorPattern": "", "BuildRetry": false, "ExcludeConsoleLog": false }Agentic workflow metadata (ci-failure-scan)
Workflow artifact: ci-failure-scan
Artifact kind: kbe-verification
Verified match count: 1 hits in failure.log
Note
This issue was drafted with the help of GitHub Copilot.
Known issue validation
Build: 🔎 https://dev.azure.com/dnceng-public/public/_build/results?buildId=1619940
Error message validated:
[System.Net.Security.Tests.SslStreamTls13NetworkConformanceTests.ZeroByteWrite_OtherDataReceivedSuccessfully System.Security.Authentication.AuthenticationException : The remote certificate was rejected by the provided RemoteCertificateValidationCallback.]Result validation: ✅ Known issue matched with the provided build.
Validation performed at: 10/2/2026 12:54:17 PM UTC
Report
Summary
Known issue validation
Build: 🔎 https://dev.azure.com/dnceng-public/public/_build/results?buildId=1619940
Error message validated:
[System.Net.Security.Tests.SslStream System.Security.Authentication.AuthenticationException : The remote certificate was rejected by the provided RemoteCertificateValidationCallback.]Result validation: ✅ Known issue matched with the provided build.
Validation performed at: 10/5/2026 5:56:27 AM UTC
Report
Summary
Report
Summary