Skip to content

Using a certificate instead of a client secret #139

Description

@mikez

In the Entra admin center it says "For a higher level of assurance, we recommend using a certificate (instead of a client secret) as a credential".

Is this something that the "identity" library or "msal" can help with?
Here's a reference:
https://learn.microsoft.com/en-us/entra/identity-platform/certificate-credentials

Activity

  1. rayluo commented on Apr 11, 2024

    @rayluo
    Contributor

    By default, this web app sample demonstrates reading client_credential from an ENV VAR which is typically a client secret string.
    However, if you somehow organize your certificate information in the format described by msal.ConfidentialClientApplication's client_credential parameter, this sample is expected to use that certificate. You can give it a try.

  2. locked and limited conversation to collaborators on May 10, 2024
  3. converted this issue into a discussion #147 on May 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions