From a64ac658b5f5ad2b1de1c065c74bc4a4a2ef1773 Mon Sep 17 00:00:00 2001 From: Rick Anderson <3605364+Rick-Anderson@users.noreply.github.com> Date: Mon, 31 Oct 2022 16:30:40 -1000 Subject: [PATCH] What's new Kestrel full certificate chain improvements (#27452) * What's new Kestrel full certificate chain improvements * What's new Kestrel full certificate chain improvements --- aspnetcore/release-notes/aspnetcore-7.0.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/aspnetcore/release-notes/aspnetcore-7.0.md b/aspnetcore/release-notes/aspnetcore-7.0.md index 9c752a9df1..1f4c0ad84e 100644 --- a/aspnetcore/release-notes/aspnetcore-7.0.md +++ b/aspnetcore/release-notes/aspnetcore-7.0.md @@ -488,6 +488,10 @@ For more information, see [Shadow copying in IIS](xref:host-and-deploy/iis/advan ## Miscellaneous +### Kestrel full certificate chain improvements + +[HttpsConnectionAdapterOptions](/dotnet/api/microsoft.aspnetcore.server.kestrel.https.httpsconnectionadapteroptions?view=aspnetcore-7.0&preserve-view=true) has a new [ServerCertificateChain](/dotnet/api/microsoft.aspnetcore.server.kestrel.https.httpsconnectionadapteroptions.servercertificatechain?view=aspnetcore-7.0&preserve-view=true#microsoft-aspnetcore-server-kestrel-https-httpsconnectionadapteroptions-servercertificatechain) property of type [X509Certificate2Collection](/dotnet/api/system.security.cryptography.x509certificates.x509certificate2collection), which makes it easier to validate certificate chains by allowing a full chain including intermediate certificates to be specified. See [dotnet/aspnetcore#21513](https://github.com/dotnet/aspnetcore/issues/21513) for more details. + ### dotnet watch #### Improved console output for dotnet watch