App Service mutual TLS is disabled Affecting App Service (Web Apps) service in Azure


Severity

0.0
low
0
10
Severity Framework
Snyk CCSS
Rule category
IAM/ Authentication

Is your environment affected by this misconfiguration?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
Frameworks
CIS-AzureCIS-ControlsCSA-CCMSOC-2
  • Snyk IDSNYK-CC-00491
  • creditSnyk Research Team

Description

Client certificates allow for the app to request a certificate for incoming requests. Only clients that have a valid certificate will be able to reach the app.

How to fix?

Set properties.clientCertEnabled attribute to true.