Repository navigation
Fix mTLS PoP incorrectly rejecting sovereign cloud aliases (login.chinacloudapi.cn / login.usgovcloudapi.net) - #6153
Conversation
…ince 4.82.0)
login.chinacloudapi.cn and login.usgovcloudapi.net are valid aliases of login.partner.microsoftonline.cn and login.microsoftonline.us and support mTLS PoP; they are normalized and swapped to their {region}.mtlsauth.* endpoints downstream. Since #5684 they were hard-rejected in RegionAndMtlsDiscoveryProvider before normalization, breaking SN/I confidential-client mTLS PoP in Azure China. Remove the sovereign-alias reject list and its check (keeping the non-login host guard and the shipped MsalError.MtlsPopNotSupportedForEnvironment and message constants). Add regression coverage for both aliases in the regional and no-region mTLS endpoint tests and remove the now-invalid throws test.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e65d13d3-9f55-4d28-8224-6b08ff1bd85b
There was a problem hiding this comment.
🟢 Ready to approve
The change removes an incorrect pre-normalization rejection while preserving the login.* safety check, and the updated tests cover the restored alias-host behavior for both regional and global mTLS endpoints.
This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.
Pull request overview
Fixes a regression in mTLS Proof-of-Possession (PoP) authority validation where valid sovereign cloud alias hosts (login.chinacloudapi.cn, login.usgovcloudapi.net) were rejected before normalization to preferred-network hosts could occur. This restores expected mTLS PoP behavior for confidential-client flows configured with these legacy alias authorities.
Changes:
- Removed the hard-coded “unsupported mTLS hosts” reject list from
RegionAndMtlsDiscoveryProvider, keeping only thelogin.*host requirement. - Expanded existing mTLS PoP unit tests to cover the China and US Gov alias authorities for both regional and global (no region) endpoint resolution.
- Deleted the unit test that previously asserted these alias hosts must throw
MtlsPopNotSupportedForEnvironment.
File summaries
| File | Description |
|---|---|
| tests/Microsoft.Identity.Test.Unit/PublicApiTests/MtlsPopTests.cs | Adds coverage for sovereign alias hosts resolving to preferred-network mTLS endpoints; removes the now-invalid “unsupported sovereign hosts” test. |
| src/client/Microsoft.Identity.Client/Instance/Discovery/RegionAndMtlsDiscoveryProvider.cs | Stops rejecting valid sovereign alias login.* hosts prior to preferred-network normalization; retains non-login.* fail-fast guard. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Low
We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.
Summary
login.chinacloudapi.cn(Azure China) andlogin.usgovcloudapi.net(Azure US Government) are valid aliases oflogin.partner.microsoftonline.cnandlogin.microsoftonline.usrespectively (seeKnownMetadataProvider). Both clouds support mTLS Proof-of-Possession, and these aliases are normalized to their preferred-network host and swapped to the correct{region}.mtlsauth.*endpoint during region resolution.Since #5684,
RegionAndMtlsDiscoveryProvider.GetMetadataAsynchard-rejected these alias hosts withMtlsPopNotSupportedForEnvironmentbefore that normalization ran. This broke mTLS PoP for confidential-client (SN/I) flows configured with the alias authority — most notably Azure China vialogin.chinacloudapi.cn.Fix
s_unsupportedMtlsHostsreject list and its check inRegionAndMtlsDiscoveryProvider. Both entries were valid aliases, so the list had no legitimate members.login.host guard unchanged, so hosts such assts.windows.net,mtlsauth.microsoft.com, andgraph.microsoft.comstill fail fast.MsalError.MtlsPopNotSupportedForEnvironmentand the associated message constants are retained.Resulting endpoints:
login.chinacloudapi.cn{region}.mtlsauth.partner.microsoftonline.cnmtlsauth.partner.microsoftonline.cnlogin.usgovcloudapi.net{region}.mtlsauth.microsoftonline.usmtlsauth.microsoftonline.usTests
login.chinacloudapi.cnandlogin.usgovcloudapi.netcases toPublicAndSovereignCloud_UsesPreferredNetwork_AndNoDiscovery_Async(regional) andPublicAndSovereignCloud_NoRegion_UsesGlobalMtlsEndpoint_Async(global / no region).UnsupportedSovereignHosts_ThrowsMsalClientException_Async.dotnet test ... --filter FullyQualifiedName~MtlsPopTests -f net8.0→ 79 passed, 0 failed.Regression range
Introduced in 4.82.0 (#5684). This restores the pre-4.82.0 behavior for these sovereign aliases.