HttpClient(AndroidMessageHandler) with NTLM v2 auth and Self Signed Certificate returns 401 Unauthorized
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- android, csharp
- Domain
- authentication, mobile, networking
Research direction
Start at AndroidMessageHandler and the shown CustomAndroidMessageHandler.WriteRequestContentToOutput override, then reproduce the NTLM v2 flow against the self-signed and public-certificate Exchange endpoints. The empty reproduction section and missing configuration leave the failure to be narrowed down; done means explaining the differing 401 behavior and establishing whether the self-signed case can work.
Written by the indexing model from the issue text.
Description
Description
I'm using an on-premise exchange server with NTLM v2 authentication.
When attempting to authenticate using HttpClient and AndroidMessageHandler, I encounter a 401 Unauthorized error, specifically due to a self-signed certificate. Interestingly, when using a public certificate, authentication proceeds without any issues.
Old ticket: https://github.com/dotnet/runtime/issues/102107
Issue still reproducible using .NET9
Here parts of the code:
var _httpClientHandler = new CustomAndroidMessageHandler();
var _credentials = new CredentialCache
{
{ new Uri(serverEndpoint), "NTLM", new NetworkCredential(emailEntry.Text, passwordEntry.Text)}
};
_httpClientHandler.ServerCertificateCustomValidationCallback = (sender, cert, chain, sslPolicyErrors) => { return true; };
_httpClientHandler.Credentials = _credentials;
HttpClient httpclient = new HttpClient(_httpClientHandler);
public class CustomAndroidMessageHandler : AndroidMessageHandler
{
protected override async Task WriteRequestContentToOutput(
HttpRequestMessage request,
HttpURLConnection httpConnection,
CancellationToken cancellationToken)
{
var stream = await request.Content.ReadAsStreamAsync().ConfigureAwait(false);
await stream.CopyToAsync(httpConnection.OutputStream!, 4096, cancellationToken).ConfigureAwait(false);
if (stream.CanSeek)
{
stream.Seek(0, SeekOrigin.Begin);
}
}
}
I added
<AndroidUseNegotiateAuthentication>true</AndroidUseNegotiateAuthentication>
in csproj
Reproduction Steps
.
Expected behavior
Working.
Actual behavior
401 Unauthorized.
Regression?
No response
Known Workarounds
No response
Configuration
No response
Other information
No response
- Dominant language
- C#
- Stars
- 18.3k
- Forks
- 5.6k
- PR merge metrics
- PR metrics pending
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dotnet/runtime
-
agentic-workflows untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
area-System.Reflection blocking-clean-ci-optional Known Build Error os-mac-os-x untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
area-CodeGen-coreclr untriaged
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
agentic-workflows untriaged
Difficulty 1/5 Under an hour Newbie friendliness 78/100
-
area-VM-meta-mono untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
:watch: Not Triaged 11.0 fundamentals/subsvc
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
dotnet/AspNetCore.Docs#37699 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
SubtitleEdit/subtitleedit#15108 · 1 comment ·
-
area/docs-content Bug pulumi/docs
Difficulty 1/5 1-3 hours Newbie friendliness 94/100
-
Create parent directories only after the containment check in InstallHelper.TryExtractToDirectory Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PowerShell/PSResourceGet#2056 ·