[docs] Document explicit Kestrel certificate configuration preservation - #1669
Draft
aspire-repo-bot[bot] wants to merge 1 commit into
Draft
aspire-repo-bot[bot] wants to merge 1 commit into
aspire-repo-bot[bot] wants to merge 1 commit into
Conversation
Adds a note to the certificate-configuration doc explaining that WithProjectDefaults preserves an existing explicit Kestrel certificate selection (Path, KeyPath, or Subject) instead of overwriting it with the default PFX mapping, per microsoft/aspire#20133. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
14 tasks
Contributor
Author
Frontend HTML artifact readyThe latest frontend build uploaded the This comment updates automatically when a new frontend build artifact is uploaded. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documents changes from microsoft/aspire#20133
@karolz-msTargeting
release/13.6based on the source PR milestone13.6.Why this is needed
microsoft/aspire#20133 fixes a bug where
WithProjectDefaults()would overwrite an explicitly configured Kestrel certificate for .NET project resources with TLS-enabled endpoints. When a resource already used an explicit PEM certificate/key pair (or a certificate storeSubject) viaWithHttpsCertificateConfiguration, Aspire's default PFX mapping replacedKestrel__Certificates__Default__Pathwhile leavingKeyPathin place, producing a mixed PFX/PEM configuration that Kestrel rejected with "The provided key file is missing or invalid."The fix preserves the entire existing certificate configuration (untouched) whenever
Kestrel__Certificates__Default__Path,Kestrel__Certificates__Default__KeyPath, orKestrel__Certificates__Default__Subjectis already present (matched case-insensitively), and only falls back to the default PFX mapping when none of those keys exist.What changed
Added a note to
src/frontend/src/content/docs/app-host/certificate-configuration.mdx, in the "Customize certificate configuration" section, explaining:WithProjectDefaultsmaps the available HTTPS certificate to Kestrel's default PFX environment variables for .NET project resources with TLS-enabled endpoints.Kestrel__Certificates__Default__Path,Kestrel__Certificates__Default__KeyPath, orKestrel__Certificates__Default__Subject.Files modified
src/frontend/src/content/docs/app-host/certificate-configuration.mdx(updated existing page — added an<Aside type="note">in the "Customize certificate configuration" section)