Skip to content

Document the 1.5 certificate validation change in the README - #56

Merged
ademar merged 1 commit into
masterfrom
docs/upgrading-to-1.5
Sep 24, 2026
Merged

ademar merged 1 commit into
masterfrom
docs/upgrading-to-1.5

Conversation

@ademar

@ademar ademar commented Sep 24, 2026

Copy link
Copy Markdown
Member

Summary

Adds an Upgrading to 1.5 section to the README, after the install instructions:

  • Why the change: from 1.5.0, TcpTransport validates the registry's server certificate (trusted chain, matching host name, not expired). Earlier versions accepted any certificate.
  • Who's affected: only test (OT&E) environments with self-signed certificates. Production registries need no change.
  • The fix: a sample ServerCertificateValidationCallback that pins the test certificate's SHA-256 fingerprint instead of returning true.
  • Getting the fingerprint: an openssl command.
  • .NET Framework: a SHA-1 fallback, since GetCertHashString(HashAlgorithmName) needs .NET Core 3.0+.

Testing

I ran the README sample against real servers, using the fingerprint from the openssl command:

Setup Result
self-signed.badssl.com, correct fingerprint connected
self-signed.badssl.com, wrong fingerprint rejected with AuthenticationException
www.nuget.org (valid certificate) connected

The README is packed into the NuGet package, so nuget.org will show this section from the next release.

🤖 Generated with Claude Code

Explain that TcpTransport now validates the registry's certificate,
and show test environments with self-signed certificates how to pin
the certificate's SHA-256 fingerprint through
ServerCertificateValidationCallback instead of accepting any.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ademar
ademar merged commit da7546d into master Sep 24, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant