Eigenverft.WebLib.Kestrel.Sni
1.0.0.5
dotnet add package Eigenverft.WebLib.Kestrel.Sni --version 1.0.0.5
NuGet\Install-Package Eigenverft.WebLib.Kestrel.Sni -Version 1.0.0.5
<PackageReference Include="Eigenverft.WebLib.Kestrel.Sni" Version="1.0.0.5" />
<PackageVersion Include="Eigenverft.WebLib.Kestrel.Sni" Version="1.0.0.5" />
<PackageReference Include="Eigenverft.WebLib.Kestrel.Sni" />
paket add Eigenverft.WebLib.Kestrel.Sni --version 1.0.0.5
#r "nuget: Eigenverft.WebLib.Kestrel.Sni, 1.0.0.5"
#:package Eigenverft.WebLib.Kestrel.Sni@1.0.0.5
#addin nuget:?package=Eigenverft.WebLib.Kestrel.Sni&version=1.0.0.5
#tool nuget:?package=Eigenverft.WebLib.Kestrel.Sni&version=1.0.0.5
Eigenverft.WebLib.Kestrel.Sni
Configuration-driven Kestrel HTTP/HTTPS listeners with SNI certificate selection and controlled certificate recovery.
✨ At a glance
| Capability | Details |
|---|---|
| Entry point | ConfigureKestrelSniFromConfiguration(...) configures listeners from KestrelSettings. |
| Certificate maps | Selects a PFX from CertificatesMappingSettings by requested SNI host. |
| Dependencies | Uses Eigenverft.NetLib.Security.Certificates transitively for managed certificate handling. |
📦 Installation
dotnet add package Eigenverft.WebLib.Kestrel.Sni
🚀 Quick start
Add configuration sources before building the app, then call the extension once:
using Eigenverft.WebLib.Kestrel.Sni;
builder.WebHost.ConfigureKestrelSniFromConfiguration();
A minimal configuration shape is:
{
"KestrelSettings": {
"HTTP_PORT": 8080,
"HTTPS_PORT": 8443,
"ListenScope": "Localhost",
"Protocols": "Http1AndHttp2",
"PreferLongestSuffixMatch": true,
"TlsProtocolPolicy": "Default"
},
"CertificatesDirectory": "certs",
"CertificatesMappingSettings": [
{
"SNI": "example.com",
"FileName": "example.com.pfx",
"Password": "load-from-protected-configuration"
}
]
}
Listener and certificate behavior
The KestrelSettings section is required (override its path with kestrelSettingsSectionPath). At least one listener must be enabled; HTTPS requires a valid certificate map even for HTTP-only listener mode. Listener ports, scope, protocols, TLS policy, match preference, and certificate directory are read at startup and require a host restart to change. TlsProtocolPolicy applies only when HTTPS is enabled. The certificate directory defaults to certs below the content root; an override takes precedence, and relative paths resolve against that root.
CertificatesMappingSettings maps an SNI suffix to a FileName and optional Password. The longest matching DNS suffix is preferred by default, with a DNS-label boundary; if no SNI or suffix matches, the first configured mapping is the fallback. Keep certificate passwords in protected configuration rather than committed plaintext. Certificate file paths must remain inside the configured certificate directory.
Only certificate mappings are hot-reloadable, and the configuration provider must emit reload notifications. A failed reload retains the last-known-good generation. Recovery defaults to None: the configured PFX must load, contain a private key, and be currently valid; an unusable initial certificate fails startup. PreserveExisting can generate a memory-only self-signed fallback without replacing the file. ReplaceExpired manages missing or expired PFX files; ReplaceAnyUnusable is intended only for fully application-managed files. Additional self-signed DNS/IP names apply only when recovery generates a certificate.
🎯 Target frameworks
Targets net8.0 and net10.0; .NET 9 can consume the compatible net8.0 asset.
🔗 Project links
📄 License
MIT; see the repository license.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Eigenverft.NetLib.Security.Certificates (>= 1.0.0.3)
-
net8.0
- Eigenverft.NetLib.Security.Certificates (>= 1.0.0.3)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
Initial capability package extracted from Eigenverft.WebLib.Infrastructure.
- Configuration-driven Kestrel listeners with SNI certificate selection, TLS policy, and certificate recovery.
- Public namespaces and behavior remain compatible with the original Infrastructure implementation.