Repository navigation
Add SmtpClient.SslOptions for per-client TLS configuration - #134919
Merged
Merged
Conversation
Forward ClientCertificates to TLS options, invalidate cached connections on assignment, and document in-place mutation behavior. Replace ServicePointManager TLS settings with per-client defaults and cover all SMTP send APIs. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
|
Tagging subscribers to this area: @karelz, @dotnet/ncl |
MihaZupan
approved these changes
Oct 7, 2026
This was referenced Oct 7, 2026
Closed
Member
|
This seems to be causing a lot of failures in CI. Reverting in #135370 |
jkotas
added a commit
that referenced
this pull request
Oct 7, 2026
rzikm
added a commit
that referenced
this pull request
Oct 9, 2026
Reintroduce feature from #134919 that was reverted by #135370 due to breaking CI too much. Test failures after merging the original PR were caused by concurrent changes from #133174 (that landed in main without us rerunning CI on the original PR). Fixed by disabling TLS resumption to force certificate validation callbacks to run when tests depend on them. Closes #135354 --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implement the approved
SmtpClient.SslOptionsAPI so applications can configure SMTP TLS per client instead of relying on process-wide settings.SslClientAuthenticationOptionsand use connection-specific copies for synchronous and asynchronous TLS authentication. A nullTargetHostdefaults to the current SMTP host without modifying the caller's options.ClientCertificatessupported without obsoletion and forward it toSslOptions.ClientCertificates.SslOptionsis assigned, including assignment of the same instance. In-place edits, including edits to nested certificate collections, do not invalidate the current connection. XML remarks explain the limitation and reassignment workaround.Compatibility
SMTP TLS no longer uses
ServicePointManager.SecurityProtocol,ServerCertificateValidationCallback, orCheckCertificateRevocationList. It usesSslClientAuthenticationOptionsdefaults instead. Applications using these global settings must migrate toSslOptions.EnabledSslProtocols,RemoteCertificateValidationCallback, andCertificateRevocationCheckMode, respectively.EnableSslstill controls STARTTLS.This is an intentional behavioral breaking change that needs release documentation. The unrelated
SmtpClient.ServicePointAPI is unchanged.Validation
Fixes: #120965
Resolves #120965
Note
This pull request was created with GitHub Copilot.