Skip to content

Add SmtpClient.SslOptions for per-client TLS configuration - #134919

Merged
rzikm merged 1 commit into
dotnet:mainfrom
rzikm:rzikm/smtpclient-ssl-options
Oct 7, 2026
Merged

rzikm merged 1 commit into
dotnet:mainfrom
rzikm:rzikm/smtpclient-ssl-options

Conversation

@rzikm

@rzikm rzikm commented Sep 30, 2026

Copy link
Copy Markdown
Member

Summary

Implement the approved SmtpClient.SslOptions API so applications can configure SMTP TLS per client instead of relying on process-wide settings.

  • Lazily initialize SslClientAuthenticationOptions and use connection-specific copies for synchronous and asynchronous TLS authentication. A null TargetHost defaults to the current SMTP host without modifying the caller's options.
  • Keep ClientCertificates supported without obsoletion and forward it to SslOptions.ClientCertificates.
  • Invalidate the cached connection whenever SslOptions is assigned, including assignment of the same instance. In-place edits, including edits to nested certificate collections, do not invalidate the current connection. XML remarks explain the limitation and reassignment workaround.
  • Update the reference API and browser/WASI unsupported-platform implementation.

Compatibility

SMTP TLS no longer uses ServicePointManager.SecurityProtocol, ServerCertificateValidationCallback, or CheckCertificateRevocationList. It uses SslClientAuthenticationOptions defaults instead. Applications using these global settings must migrate to SslOptions.EnabledSslProtocols, RemoteCertificateValidationCallback, and CertificateRevocationCheckMode, respectively. EnableSsl still controls STARTTLS.

This is an intentional behavioral breaking change that needs release documentation. The unrelated SmtpClient.ServicePoint API is unchanged.

Validation

  • Clean Windows baseline and all System.Net.Mail library targets built successfully, with no warnings or errors.
  • 518 functional tests and 411 unit tests passed on Windows, with zero failures or skips.
  • Coverage includes all three send APIs, option defaults and forwarding, certificate validation, target host, TLS protocol and ALPN selection, connection reuse and reassignment, assignment during sends, and independence from global TLS settings.
  • Non-Windows runtime execution was not performed.

Fixes: #120965

Resolves #120965

Note

This pull request was created with GitHub Copilot.

Forward ClientCertificates to TLS options, invalidate cached connections on assignment, and document in-place mutation behavior. Replace ServicePointManager TLS settings with per-client defaults and cover all SMTP send APIs.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @karelz, @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

@jkotas

jkotas commented Oct 7, 2026

Copy link
Copy Markdown
Member

This seems to be causing a lot of failures in CI. Reverting in #135370

@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Oct 8, 2026
rzikm added a commit that referenced this pull request Oct 9, 2026
Reintroduce feature from #134919
that was reverted by #135370 due
to breaking CI too much.

Test failures after merging the original PR were caused by concurrent
changes from #133174 (that landed
in main without us rerunning CI on the original PR). Fixed by disabling
TLS resumption to force certificate validation callbacks to run when
tests depend on them.

Closes #135354

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[API Proposal]: SmtpClient.SslOptions

3 participants