Do not bypass certificates validation

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Metadata

ID: csharp-security/check-server-ssl-sertificates

Language: C#

Severity: Error

Category: Security

CWE: 295

Description

Never bypass certificate validation. Certificates should be correctly checked to avoid attacks from untrusted sources.

Learn More

Non-Compliant Code Examples

using System.Net;
using System.Net.Http;

class MyClass {
public static void connect()
    {
        ServicePointManager.ServerCertificateValidationCallback +=
            (sender, certificate, chain, errors) => {
                return true;
            };

    }
}
https://static.datadoghq.com/static/images/logos/github_avatar.svg https://static.datadoghq.com/static/images/logos/vscode_avatar.svg jetbrains

Seamless integrations. Try Datadog Code Analysis