SSLPinning on .net standard 2.1

Viewed 53

I want to check the certificate during the negotiation time of an HttpRequest made over an System.Net.Http HttpClient. I found there are multiple ways to do it, one of it is with:

ServicePointManager.ServerCertificateValidationCallback = new RemoteCertificateValidationCallback(VerifyServer);

Which I don't like because I want to do it per HttpClient. I've notice I can inject a HttpClientHandler through the constructor, but the method I want to use to check the thumbprint of the certificate is hidden:

[EditorBrowsable(EditorBrowsableState.Never)]
public Func<HttpRequestMessage, X509Certificate2, X509Chain, SslPolicyErrors, bool> ServerCertificateCustomValidationCallback { get; set; }

Is there any specific reason why is hidden? Is it safe to use this method to check the certificate?

Thanks!

0 Answers
Related