trust/skip TLS verification for MCP HTTP servers
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 11.2k
- Forks
- 1.9k
- Avg merge
- 14h 16m
- Merged PRs (30d)
- 6
Description
Describe the feature or problem you'd like to solve
trust/skip TLS verification for MCP HTTP servers with invalid SAN certs (rustls hard-fails, no insecure option)
Proposed solution
Copilot CLI cannot connect to a remote HTTP MCP server whose TLS certificate has an invalid Subject Alternative Name (e.g., a literal * instead of a proper wildcard/IP SAN), even after the cert's issuing CA is explicitly trusted. There is no config option or environment variable to bypass hostname/certificate verification for a specific MCP server, which blocks use cases like connecting to on-prem/IoT devices with embedded mcp server and self-managed certificates addressed by IP Address.
Steps to reproduce
- device that presents a self-signed certificate whose Subject/SAN is not a valid match for the IP address (e.g., CN/SAN = * )
- Export and trust the CA: export NODE_EXTRA_CA_CERTS=~/ctrlx.pem
- Run copilot , then /mcp — the server still fails to connect.
Requested behavior
The CLI offers a supported way to relax verification for a specific MCP server (e.g., a per-server tls.insecureSkipVerify or honoring a documented env var), similar to how curl -k or Node's NODE_TLS_REJECT_UNAUTHORIZED=0 work for other tools.
Example prompts or workflows
NA
Additional context
• Related: #4364 documents a similar underlying issue (rustls/rustls-platform-verifier being stricter than curl/Node/Chrome for enterprise MCP registry TLS), suggesting this is a broader gap in the Rust-based MCP networking layer, not specific to one code path.
• For comparison, Claude Code and Gemini CLI's MCP clients run on Node.js, so NODE_TLS_REJECT_UNAUTHORIZED=0 works as an (insecure) escape hatch there; Copilot CLI has no equivalent because of the runtime split.
• Use case: connecting to on-prem/IoT devices reachable only via IP address with vendor-managed self-signed certificates that can't easily be reissued with a proper SAN.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Read related issue #4364, then trace the Rust-based MCP networking layer used when /mcp connects to an HTTP server. Reproduce the failure with the invalid-SAN certificate and determine where a per-server insecure option or documented environment variable would apply; done means the CLI can connect to that server through the supported configuration.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- networking, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 38/100