Skip to content

Fix mTLS PoP incorrectly rejecting sovereign cloud aliases (login.chinacloudapi.cn / login.usgovcloudapi.net) - #6153

Merged
Gladwin Johnson VR (gladjohn) merged 1 commit into
mainfrom
gladjohn/mtls-pop-sovereign-alias-fix
Jul 31, 2026
Merged

Gladwin Johnson VR (gladjohn) merged 1 commit into
mainfrom
gladjohn/mtls-pop-sovereign-alias-fix

Conversation

@gladjohn

Copy link
Copy Markdown
Contributor

Summary

login.chinacloudapi.cn (Azure China) and login.usgovcloudapi.net (Azure US Government) are valid aliases of login.partner.microsoftonline.cn and login.microsoftonline.us respectively (see KnownMetadataProvider). Both clouds support mTLS Proof-of-Possession, and these aliases are normalized to their preferred-network host and swapped to the correct {region}.mtlsauth.* endpoint during region resolution.

Since #5684, RegionAndMtlsDiscoveryProvider.GetMetadataAsync hard-rejected these alias hosts with MtlsPopNotSupportedForEnvironment before that normalization ran. This broke mTLS PoP for confidential-client (SN/I) flows configured with the alias authority — most notably Azure China via login.chinacloudapi.cn.

Fix

  • Remove the s_unsupportedMtlsHosts reject list and its check in RegionAndMtlsDiscoveryProvider. Both entries were valid aliases, so the list had no legitimate members.
  • Keep the non-login. host guard unchanged, so hosts such as sts.windows.net, mtlsauth.microsoft.com, and graph.microsoft.com still fail fast.
  • No public API change — MsalError.MtlsPopNotSupportedForEnvironment and the associated message constants are retained.

Resulting endpoints:

Authority host Regional No region (global)
login.chinacloudapi.cn {region}.mtlsauth.partner.microsoftonline.cn mtlsauth.partner.microsoftonline.cn
login.usgovcloudapi.net {region}.mtlsauth.microsoftonline.us mtlsauth.microsoftonline.us

Tests

  • Added login.chinacloudapi.cn and login.usgovcloudapi.net cases to PublicAndSovereignCloud_UsesPreferredNetwork_AndNoDiscovery_Async (regional) and PublicAndSovereignCloud_NoRegion_UsesGlobalMtlsEndpoint_Async (global / no region).
  • Removed the now-invalid UnsupportedSovereignHosts_ThrowsMsalClientException_Async.
  • dotnet test ... --filter FullyQualifiedName~MtlsPopTests -f net8.0 → 79 passed, 0 failed.

Regression range

Introduced in 4.82.0 (#5684). This restores the pre-4.82.0 behavior for these sovereign aliases.

…ince 4.82.0)

login.chinacloudapi.cn and login.usgovcloudapi.net are valid aliases of login.partner.microsoftonline.cn and login.microsoftonline.us and support mTLS PoP; they are normalized and swapped to their {region}.mtlsauth.* endpoints downstream. Since #5684 they were hard-rejected in RegionAndMtlsDiscoveryProvider before normalization, breaking SN/I confidential-client mTLS PoP in Azure China. Remove the sovereign-alias reject list and its check (keeping the non-login host guard and the shipped MsalError.MtlsPopNotSupportedForEnvironment and message constants). Add regression coverage for both aliases in the regional and no-region mTLS endpoint tests and remove the now-invalid throws test.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e65d13d3-9f55-4d28-8224-6b08ff1bd85b
Copilot AI review requested due to automatic review settings July 30, 2026 20:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Ready to approve

The change removes an incorrect pre-normalization rejection while preserving the login.* safety check, and the updated tests cover the restored alias-host behavior for both regional and global mTLS endpoints.

This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.

Pull request overview

Fixes a regression in mTLS Proof-of-Possession (PoP) authority validation where valid sovereign cloud alias hosts (login.chinacloudapi.cn, login.usgovcloudapi.net) were rejected before normalization to preferred-network hosts could occur. This restores expected mTLS PoP behavior for confidential-client flows configured with these legacy alias authorities.

Changes:

  • Removed the hard-coded “unsupported mTLS hosts” reject list from RegionAndMtlsDiscoveryProvider, keeping only the login.* host requirement.
  • Expanded existing mTLS PoP unit tests to cover the China and US Gov alias authorities for both regional and global (no region) endpoint resolution.
  • Deleted the unit test that previously asserted these alias hosts must throw MtlsPopNotSupportedForEnvironment.
File summaries
File Description
tests/Microsoft.Identity.Test.Unit/PublicApiTests/MtlsPopTests.cs Adds coverage for sovereign alias hosts resolving to preferred-network mTLS endpoints; removes the now-invalid “unsupported sovereign hosts” test.
src/client/Microsoft.Identity.Client/Instance/Discovery/RegionAndMtlsDiscoveryProvider.cs Stops rejecting valid sovereign alias login.* hosts prior to preferred-network normalization; retains non-login.* fail-fast guard.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Low

We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.

@gladjohn
Gladwin Johnson VR (gladjohn) marked this pull request as ready for review July 30, 2026 20:58
@gladjohn
Gladwin Johnson VR (gladjohn) requested a review from a team as a code owner July 30, 2026 20:58
@gladjohn
Gladwin Johnson VR (gladjohn) merged commit fd873f2 into main Jul 31, 2026
17 checks passed
@gladjohn
Gladwin Johnson VR (gladjohn) deleted the gladjohn/mtls-pop-sovereign-alias-fix branch July 31, 2026 15:41
This was referenced Aug 20, 2026
This was referenced Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants