< Summary

Line coverage
0%
Covered lines: 0
Uncovered lines: 526
Coverable lines: 526
Total lines: 950
Line coverage: 0%
Branch coverage
0%
Covered branches: 0
Total branches: 197
Branch coverage: 0%
Method coverage

Feature is only available for sponsors

Upgrade to PRO version

Metrics

MethodBranch coverage Cyclomatic complexity NPath complexity Sequence coverage
.cctor()100%110%
.ctor(...)100%110%
.ctor(...)100%110%
Dispose(...)0%220%
DisposeAsync()0%660%
BeginAuthenticateAsClient(...)100%110%
BeginAuthenticateAsClient(...)100%110%
BeginAuthenticateAsClient(...)100%110%
BeginAuthenticateAsClient(...)100%110%
BeginAuthenticateAsClient(...)100%110%
EndAuthenticateAsClient(...)100%110%
AuthenticateAsServer()100%110%
AuthenticateAsServer(...)100%110%
AuthenticateAsServer(...)100%110%
AuthenticateAsServer(...)100%110%
BeginAuthenticateAsServer(...)100%110%
BeginAuthenticateAsServer(...)100%110%
BeginAuthenticateAsServer(...)100%110%
BeginAuthenticateAsServer(...)100%110%
EndAuthenticateAsServer(...)100%110%
AuthenticateAsClient()100%110%
AuthenticateAsClient(...)100%110%
AuthenticateAsClient(...)100%110%
AuthenticateAsClient(...)100%110%
AuthenticateAsClient(...)100%110%
AuthenticateAsClientAsync()100%110%
AuthenticateAsClientAsync(...)100%110%
AuthenticateAsClientAsync(...)100%110%
AuthenticateAsClientAsync(...)100%110%
AuthenticateAsClientAsync(...)100%110%
AuthenticateAsServerAsync()100%110%
AuthenticateAsServerAsync(...)100%110%
AuthenticateAsServerAsync(...)100%110%
AuthenticateAsServerAsync(...)100%110%
SetLength(...)100%110%
Seek(...)100%110%
Flush()100%110%
FlushAsync(...)100%110%
Read(...)0%220%
ReadAsync(...)0%220%
ReadAsync(...)0%30300%
ReadAllAsync(System.IO.Stream,System.Memory`1<System.Byte>,System.Boolean,System.Threading.CancellationToken)0%660%
Write(...)0%220%
WriteAsync(...)0%220%
WriteAsync(...)0%220%
WriteAsync(...)0%10100%
BeginRead(...)100%110%
EndRead(...)100%110%
BeginWrite(...)100%110%
EndWrite(...)100%110%
ThrowIfExceptional()0%220%
ThrowExceptional(System.Runtime.ExceptionServices.ExceptionDispatchInfo)100%110%
ValidateCreateContext(...)0%660%
ValidateCreateContext(...)0%20200%
SetFailed(...)0%660%
ThrowIfFailed(...)0%440%
AuthenticateAsync(...)0%440%
SendBlobAsync(...)0%45450%
ReceiveBlobAsync(...)0%18180%
SendAuthResetSignalAndThrowAsync(...)100%110%
ThrowCredentialException(...)0%660%

File(s)

https://raw.githubusercontent.com/dotnet/runtime/811a7eabb75c42db53440e8ba3f60c07511cfd1f/src/libraries/System.Net.Security/src/System/Net/Security/NegotiateStream.cs

#LineLine coverage
 1// Licensed to the .NET Foundation under one or more agreements.
 2// The .NET Foundation licenses this file to you under the MIT license.
 3
 4using System.Buffers;
 5using System.Buffers.Binary;
 6using System.ComponentModel;
 7using System.Diagnostics;
 8using System.Diagnostics.CodeAnalysis;
 9using System.IO;
 10using System.Runtime.CompilerServices;
 11using System.Runtime.ExceptionServices;
 12using System.Runtime.Versioning;
 13using System.Security.Authentication;
 14using System.Security.Authentication.ExtendedProtection;
 15using System.Security.Principal;
 16using System.Threading;
 17using System.Threading.Tasks;
 18
 19namespace System.Net.Security
 20{
 21    /// <summary>
 22    /// Provides a stream that uses the Negotiate security protocol to authenticate the client, and optionally the serve
 23    /// </summary>
 24    public partial class NegotiateStream : AuthenticatedStream
 25    {
 26        /// <summary>Set as the _exception when the instance is disposed.</summary>
 027        private static readonly ExceptionDispatchInfo s_disposedSentinel = ExceptionDispatchInfo.Capture(new ObjectDispo
 28
 29        private const int ERROR_TRUST_FAILURE = 1790;   // Used to serialize protectionLevel or impersonationLevel misma
 30        private const int MaxReadFrameSize = 64 * 1024;
 31        private const int MaxWriteDataSize = 63 * 1024; // 1k for the framing and trailer that is always less as per SSP
 32        private const string DefaultPackage = NegotiationInfoClass.Negotiate;
 33
 34#pragma warning disable CA1825 // used in reference comparison, requires unique object identity
 035        private static readonly byte[] s_emptyMessage = new byte[0];
 36#pragma warning restore CA1825
 37
 38        private readonly byte[] _writeHeader;
 39        private readonly byte[] _readHeader;
 40        private byte[] _readBuffer;
 41        private int _readBufferOffset;
 42        private int _readBufferCount;
 43        private ArrayBufferWriter<byte>? _writeBuffer;
 44
 45        private volatile bool _writeInProgress;
 46        private volatile bool _readInProgress;
 47        private volatile bool _authInProgress;
 48
 49        private ExceptionDispatchInfo? _exception;
 50        private StreamFramer? _framer;
 51        private NegotiateAuthentication? _context;
 52        private bool _canRetryAuthentication;
 53        private ProtectionLevel _expectedProtectionLevel;
 54        private TokenImpersonationLevel _expectedImpersonationLevel;
 55        private ExtendedProtectionPolicy? _extendedProtectionPolicy;
 56
 57        private bool isNtlm;
 58
 59        /// <summary>
 60        /// SSPI does not send a server ack on successful auth.
 61        /// This is a state variable used to gracefully handle auth confirmation.
 62        /// </summary>
 63        private bool _remoteOk;
 64
 065        public NegotiateStream(Stream innerStream) : this(innerStream, false)
 066        {
 067        }
 68
 069        public NegotiateStream(Stream innerStream, bool leaveInnerStreamOpen) : base(innerStream, leaveInnerStreamOpen)
 070        {
 071            _writeHeader = new byte[4];
 072            _readHeader = new byte[4];
 073            _readBuffer = Array.Empty<byte>();
 074        }
 75
 76        protected override void Dispose(bool disposing)
 077        {
 78            try
 079            {
 080                _exception = s_disposedSentinel;
 081                _context?.Dispose();
 082            }
 83            finally
 084            {
 085                base.Dispose(disposing);
 086            }
 087        }
 88
 89        public override async ValueTask DisposeAsync()
 090        {
 91            try
 092            {
 093                _exception = s_disposedSentinel;
 094                _context?.Dispose();
 095            }
 96            finally
 097            {
 098                await base.DisposeAsync().ConfigureAwait(false);
 099            }
 0100        }
 101
 102        public virtual IAsyncResult BeginAuthenticateAsClient(AsyncCallback? asyncCallback, object? asyncState) =>
 0103            BeginAuthenticateAsClient((NetworkCredential)CredentialCache.DefaultCredentials, binding: null, string.Empty
 0104                                      asyncCallback, asyncState);
 105
 106        public virtual IAsyncResult BeginAuthenticateAsClient(NetworkCredential credential, string targetName, AsyncCall
 0107            BeginAuthenticateAsClient(credential, binding: null, targetName, ProtectionLevel.EncryptAndSign, TokenImpers
 0108                                      asyncCallback, asyncState);
 109
 110        public virtual IAsyncResult BeginAuthenticateAsClient(NetworkCredential credential, ChannelBinding? binding, str
 0111            BeginAuthenticateAsClient(credential, binding, targetName, ProtectionLevel.EncryptAndSign, TokenImpersonatio
 0112                                      asyncCallback, asyncState);
 113
 114        public virtual IAsyncResult BeginAuthenticateAsClient(
 115            NetworkCredential credential, string targetName, ProtectionLevel requiredProtectionLevel, TokenImpersonation
 116            AsyncCallback? asyncCallback, object? asyncState) =>
 0117            BeginAuthenticateAsClient(credential, binding: null, targetName, requiredProtectionLevel, allowedImpersonati
 0118                                      asyncCallback, asyncState);
 119
 120        public virtual IAsyncResult BeginAuthenticateAsClient(
 121            NetworkCredential credential, ChannelBinding? binding, string targetName, ProtectionLevel requiredProtection
 122            AsyncCallback? asyncCallback, object? asyncState) =>
 0123            TaskToAsyncResult.Begin(AuthenticateAsClientAsync(credential, binding, targetName, requiredProtectionLevel, 
 124
 0125        public virtual void EndAuthenticateAsClient(IAsyncResult asyncResult) => TaskToAsyncResult.End(asyncResult);
 126
 127        public virtual void AuthenticateAsServer() =>
 0128            AuthenticateAsServer((NetworkCredential)CredentialCache.DefaultCredentials, policy: null, ProtectionLevel.En
 129
 130        public virtual void AuthenticateAsServer(ExtendedProtectionPolicy? policy) =>
 0131            AuthenticateAsServer((NetworkCredential)CredentialCache.DefaultCredentials, policy, ProtectionLevel.EncryptA
 132
 133        public virtual void AuthenticateAsServer(NetworkCredential credential, ProtectionLevel requiredProtectionLevel, 
 0134            AuthenticateAsServer(credential, policy: null, requiredProtectionLevel, requiredImpersonationLevel);
 135
 136        public virtual void AuthenticateAsServer(NetworkCredential credential, ExtendedProtectionPolicy? policy, Protect
 0137        {
 0138            ValidateCreateContext(DefaultPackage, credential, string.Empty, policy, requiredProtectionLevel, requiredImp
 0139            AuthenticateAsync<SyncReadWriteAdapter>(default(CancellationToken)).GetAwaiter().GetResult();
 0140        }
 141
 142        public virtual IAsyncResult BeginAuthenticateAsServer(AsyncCallback? asyncCallback, object? asyncState) =>
 0143            BeginAuthenticateAsServer((NetworkCredential)CredentialCache.DefaultCredentials, policy: null, ProtectionLev
 144
 145        public virtual IAsyncResult BeginAuthenticateAsServer(ExtendedProtectionPolicy? policy, AsyncCallback? asyncCall
 0146            BeginAuthenticateAsServer((NetworkCredential)CredentialCache.DefaultCredentials, policy, ProtectionLevel.Enc
 147
 148        public virtual IAsyncResult BeginAuthenticateAsServer(
 149            NetworkCredential credential, ProtectionLevel requiredProtectionLevel, TokenImpersonationLevel requiredImper
 150            AsyncCallback? asyncCallback, object? asyncState) =>
 0151            BeginAuthenticateAsServer(credential, policy: null, requiredProtectionLevel, requiredImpersonationLevel, asy
 152
 153        public virtual IAsyncResult BeginAuthenticateAsServer(
 154            NetworkCredential credential, ExtendedProtectionPolicy? policy, ProtectionLevel requiredProtectionLevel, Tok
 155            AsyncCallback? asyncCallback, object? asyncState) =>
 0156            TaskToAsyncResult.Begin(AuthenticateAsServerAsync(credential, policy, requiredProtectionLevel, requiredImper
 157
 0158        public virtual void EndAuthenticateAsServer(IAsyncResult asyncResult) => TaskToAsyncResult.End(asyncResult);
 159
 160        public virtual void AuthenticateAsClient() =>
 0161            AuthenticateAsClient((NetworkCredential)CredentialCache.DefaultCredentials, binding: null, string.Empty, Pro
 162
 163        public virtual void AuthenticateAsClient(NetworkCredential credential, string targetName) =>
 0164            AuthenticateAsClient(credential, binding: null, targetName, ProtectionLevel.EncryptAndSign, TokenImpersonati
 165
 166        public virtual void AuthenticateAsClient(NetworkCredential credential, ChannelBinding? binding, string targetNam
 0167            AuthenticateAsClient(credential, binding, targetName, ProtectionLevel.EncryptAndSign, TokenImpersonationLeve
 168
 169        public virtual void AuthenticateAsClient(
 170            NetworkCredential credential, string targetName, ProtectionLevel requiredProtectionLevel, TokenImpersonation
 0171            AuthenticateAsClient(credential, binding: null, targetName, requiredProtectionLevel, allowedImpersonationLev
 172
 173        public virtual void AuthenticateAsClient(
 174            NetworkCredential credential, ChannelBinding? binding, string targetName, ProtectionLevel requiredProtection
 0175        {
 0176            ValidateCreateContext(DefaultPackage, isServer: false, credential, targetName, binding, requiredProtectionLe
 0177            AuthenticateAsync<SyncReadWriteAdapter>(default(CancellationToken)).GetAwaiter().GetResult();
 0178        }
 179
 180        public virtual Task AuthenticateAsClientAsync() =>
 0181            AuthenticateAsClientAsync((NetworkCredential)CredentialCache.DefaultCredentials, binding: null, string.Empty
 182
 183        public virtual Task AuthenticateAsClientAsync(NetworkCredential credential, string targetName) =>
 0184            AuthenticateAsClientAsync(credential, binding: null, targetName, ProtectionLevel.EncryptAndSign, TokenImpers
 185
 186        public virtual Task AuthenticateAsClientAsync(
 187            NetworkCredential credential, string targetName,
 188            ProtectionLevel requiredProtectionLevel,
 189            TokenImpersonationLevel allowedImpersonationLevel) =>
 0190            AuthenticateAsClientAsync(credential, binding: null, targetName, requiredProtectionLevel, allowedImpersonati
 191
 192        public virtual Task AuthenticateAsClientAsync(NetworkCredential credential, ChannelBinding? binding, string targ
 0193            AuthenticateAsClientAsync(credential, binding, targetName, ProtectionLevel.EncryptAndSign, TokenImpersonatio
 194
 195        public virtual Task AuthenticateAsClientAsync(
 196            NetworkCredential credential, ChannelBinding? binding, string targetName, ProtectionLevel requiredProtection
 197            TokenImpersonationLevel allowedImpersonationLevel)
 0198        {
 0199            ValidateCreateContext(DefaultPackage, isServer: false, credential, targetName, binding, requiredProtectionLe
 0200            return AuthenticateAsync<AsyncReadWriteAdapter>(default(CancellationToken));
 0201        }
 202
 203        public virtual Task AuthenticateAsServerAsync() =>
 0204            AuthenticateAsServerAsync((NetworkCredential)CredentialCache.DefaultCredentials, policy: null, ProtectionLev
 205
 206        public virtual Task AuthenticateAsServerAsync(ExtendedProtectionPolicy? policy) =>
 0207            AuthenticateAsServerAsync((NetworkCredential)CredentialCache.DefaultCredentials, policy, ProtectionLevel.Enc
 208
 209        public virtual Task AuthenticateAsServerAsync(NetworkCredential credential, ProtectionLevel requiredProtectionLe
 0210            AuthenticateAsServerAsync(credential, policy: null, requiredProtectionLevel, requiredImpersonationLevel);
 211
 212        public virtual Task AuthenticateAsServerAsync(
 213            NetworkCredential credential, ExtendedProtectionPolicy? policy, ProtectionLevel requiredProtectionLevel, Tok
 0214        {
 0215            ValidateCreateContext(DefaultPackage, credential, string.Empty, policy, requiredProtectionLevel, requiredImp
 0216            return AuthenticateAsync<AsyncReadWriteAdapter>(default(CancellationToken));
 0217        }
 218
 0219        public override bool IsAuthenticated => IsAuthenticatedCore;
 220
 221        [MemberNotNullWhen(true, nameof(_context))]
 0222        private bool IsAuthenticatedCore => _context != null && HandshakeComplete && _exception == null && _remoteOk;
 223
 0224        public override bool IsMutuallyAuthenticated => IsAuthenticatedCore && _context.IsMutuallyAuthenticated;
 225
 0226        public override bool IsEncrypted => IsAuthenticatedCore && _context.IsEncrypted;
 227
 0228        public override bool IsSigned => IsAuthenticatedCore && (_context.IsSigned || _context.IsEncrypted);
 229
 0230        public override bool IsServer => _context != null && _context.IsServer;
 231
 232        public virtual TokenImpersonationLevel ImpersonationLevel
 233        {
 234            get
 0235            {
 0236                ThrowIfFailed(authSuccessCheck: true);
 0237                return PrivateImpersonationLevel;
 0238            }
 239        }
 240
 0241        private TokenImpersonationLevel PrivateImpersonationLevel => _context!.ImpersonationLevel;
 242
 0243        private bool HandshakeComplete => _context!.IsAuthenticated;
 244
 0245        private bool CanGetSecureStream => _context!.IsEncrypted || _context.IsSigned;
 246
 247        public virtual IIdentity RemoteIdentity
 248        {
 249            get
 0250            {
 0251                ThrowIfFailed(authSuccessCheck: true);
 0252                return _context!.RemoteIdentity;
 0253            }
 254        }
 255
 0256        public override bool CanSeek => false;
 257
 0258        public override bool CanRead => IsAuthenticated && InnerStream.CanRead;
 259
 0260        public override bool CanTimeout => InnerStream.CanTimeout;
 261
 0262        public override bool CanWrite => IsAuthenticated && InnerStream.CanWrite;
 263
 264        public override int ReadTimeout
 265        {
 0266            get => InnerStream.ReadTimeout;
 0267            set => InnerStream.ReadTimeout = value;
 268        }
 269
 270        public override int WriteTimeout
 271        {
 0272            get => InnerStream.WriteTimeout;
 0273            set => InnerStream.WriteTimeout = value;
 274        }
 275
 0276        public override long Length => InnerStream.Length;
 277
 278        public override long Position
 279        {
 0280            get => InnerStream.Position;
 0281            set => throw new NotSupportedException(SR.net_noseek);
 282        }
 283
 284        public override void SetLength(long value) =>
 0285            InnerStream.SetLength(value);
 286
 287        public override long Seek(long offset, SeekOrigin origin) =>
 0288            throw new NotSupportedException(SR.net_noseek);
 289
 290        public override void Flush() =>
 0291            InnerStream.Flush();
 292
 293        public override Task FlushAsync(CancellationToken cancellationToken) =>
 0294            InnerStream.FlushAsync(cancellationToken);
 295
 296        public override int Read(byte[] buffer, int offset, int count)
 0297        {
 0298            ValidateBufferArguments(buffer, offset, count);
 299
 0300            ThrowIfFailed(authSuccessCheck: true);
 0301            if (!CanGetSecureStream)
 0302            {
 0303                return InnerStream.Read(buffer, offset, count);
 304            }
 305
 0306            ValueTask<int> vt = ReadAsync<SyncReadWriteAdapter>(new Memory<byte>(buffer, offset, count), default(Cancell
 0307            Debug.Assert(vt.IsCompleted, "Should have completed synchroously with sync adapter");
 0308            return vt.GetAwaiter().GetResult();
 0309        }
 310
 311        public override Task<int> ReadAsync(byte[] buffer, int offset, int count, CancellationToken cancellationToken)
 0312        {
 0313            ValidateBufferArguments(buffer, offset, count);
 314
 0315            ThrowIfFailed(authSuccessCheck: true);
 0316            if (!CanGetSecureStream)
 0317            {
 0318                return InnerStream.ReadAsync(buffer, offset, count, cancellationToken);
 319            }
 320
 0321            return ReadAsync<AsyncReadWriteAdapter>(new Memory<byte>(buffer, offset, count), cancellationToken).AsTask()
 0322        }
 323
 324        public override ValueTask<int> ReadAsync(Memory<byte> buffer, CancellationToken cancellationToken = default)
 0325        {
 0326            ThrowIfFailed(authSuccessCheck: true);
 0327            if (!CanGetSecureStream)
 0328            {
 0329                return InnerStream.ReadAsync(buffer, cancellationToken);
 330            }
 331
 0332            return ReadAsync<AsyncReadWriteAdapter>(buffer, cancellationToken);
 0333        }
 334
 335        private async ValueTask<int> ReadAsync<TIOAdapter>(Memory<byte> buffer, CancellationToken cancellationToken)
 336            where TIOAdapter : IReadWriteAdapter
 0337        {
 0338            Debug.Assert(_context is not null);
 339
 0340            if (Interlocked.Exchange(ref _readInProgress, true))
 0341            {
 0342                throw new NotSupportedException(SR.Format(SR.net_io_invalidnestedcall, "read"));
 343            }
 344
 345            try
 0346            {
 0347                ThrowIfFailed(authSuccessCheck: true);
 348
 0349                if (_readBufferCount != 0)
 0350                {
 0351                    int copyBytes = Math.Min(_readBufferCount, buffer.Length);
 0352                    if (copyBytes != 0)
 0353                    {
 0354                        _readBuffer.AsMemory(_readBufferOffset, copyBytes).CopyTo(buffer);
 0355                        _readBufferOffset += copyBytes;
 0356                        _readBufferCount -= copyBytes;
 0357                    }
 0358                    return copyBytes;
 359                }
 360
 0361                while (true)
 0362                {
 0363                    int readBytes = await ReadAllAsync(InnerStream, _readHeader, allowZeroRead: true, cancellationToken)
 0364                    if (readBytes == 0)
 0365                    {
 0366                        return 0;
 367                    }
 368
 369                    // Replace readBytes with the body size recovered from the header content.
 0370                    readBytes = BinaryPrimitives.ReadInt32LittleEndian(_readHeader);
 371
 372                    // The body carries 4 bytes for trailer size slot plus trailer, hence <= 4 frame size is always an e
 373                    // Additionally we'd like to restrict the read frame size to 64k.
 0374                    if (readBytes <= 4 || readBytes > MaxReadFrameSize)
 0375                    {
 0376                        throw new IOException(SR.net_frame_read_size);
 377                    }
 378
 379                    // Always pass InternalBuffer for SSPI "in place" decryption.
 380                    // A user buffer can be shared by many threads in that case decryption/integrity check may fail caus
 0381                    if (_readBuffer.Length < readBytes)
 0382                    {
 0383                        _readBuffer = new byte[readBytes];
 0384                    }
 385
 386                    // Note: do not assign _readBufferCount/_readBufferOffset before the read completes successfully.
 387                    // If the read throws (e.g. due to the connection closing), a subsequent Read call would otherwise
 388                    // observe a non-zero _readBufferCount and return stale/undecrypted buffer contents.
 0389                    readBytes = await ReadAllAsync(InnerStream, new Memory<byte>(_readBuffer, 0, readBytes), allowZeroRe
 390
 391                    // Decrypt into the same buffer (decrypted data size can be shrunk after decryption).
 392                    // Use locals so that on failure we do not leave _readBufferOffset/_readBufferCount in a state that
 393                    // would expose stale or undecrypted data on a subsequent Read call.
 394                    NegotiateAuthenticationStatusCode statusCode;
 0395                    int decryptedOffset = 0;
 0396                    int decryptedCount = 0;
 0397                    if (isNtlm && !_context.IsEncrypted)
 0398                    {
 399                        // Non-encrypted NTLM uses an encoding quirk
 400                        const int NtlmSignatureLength = 16;
 401
 0402                        if (readBytes < NtlmSignatureLength ||
 0403                            !_context.VerifyIntegrityCheck(_readBuffer.AsSpan(NtlmSignatureLength, readBytes - NtlmSigna
 0404                        {
 0405                            statusCode = NegotiateAuthenticationStatusCode.InvalidToken;
 0406                        }
 407                        else
 0408                        {
 0409                            decryptedOffset = NtlmSignatureLength;
 0410                            decryptedCount = readBytes - NtlmSignatureLength;
 0411                            statusCode = NegotiateAuthenticationStatusCode.Completed;
 0412                        }
 0413                    }
 414                    else
 0415                    {
 0416                        statusCode = _context.UnwrapInPlace(_readBuffer.AsSpan(0, readBytes), out decryptedOffset, out d
 0417                    }
 418
 0419                    if (statusCode != NegotiateAuthenticationStatusCode.Completed)
 0420                    {
 421                        // TODO: Better exception
 0422                        throw new IOException(SR.net_io_read);
 423                    }
 424
 0425                    _readBufferOffset = decryptedOffset;
 0426                    _readBufferCount = decryptedCount;
 427
 428                    // Decrypted data can be shrunk after decryption.
 0429                    if (_readBufferCount == 0 && buffer.Length != 0)
 0430                    {
 431                        // Read again.
 0432                        continue;
 433                    }
 434
 0435                    int copyBytes = Math.Min(_readBufferCount, buffer.Length);
 0436                    _readBuffer.AsMemory(_readBufferOffset, copyBytes).CopyTo(buffer);
 0437                    _readBufferOffset += copyBytes;
 0438                    _readBufferCount -= copyBytes;
 439
 0440                    return copyBytes;
 441                }
 442            }
 0443            catch (Exception e) when (!(e is IOException || e is OperationCanceledException))
 0444            {
 0445                throw new IOException(SR.net_io_read, e);
 446            }
 447            finally
 0448            {
 0449                _readInProgress = false;
 0450            }
 451
 452            static async ValueTask<int> ReadAllAsync(Stream stream, Memory<byte> buffer, bool allowZeroRead, Cancellatio
 0453            {
 0454                int read = await TIOAdapter.ReadAtLeastAsync(
 0455                    stream, buffer, buffer.Length, throwOnEndOfStream: false, cancellationToken).ConfigureAwait(false);
 0456                if (read < buffer.Length)
 0457                {
 0458                    if (read != 0 || !allowZeroRead)
 0459                    {
 0460                        throw new IOException(SR.net_io_eof);
 461                    }
 0462                }
 463
 0464                return read;
 0465            }
 0466        }
 467
 468        public override void Write(byte[] buffer, int offset, int count)
 0469        {
 0470            ValidateBufferArguments(buffer, offset, count);
 471
 0472            ThrowIfFailed(authSuccessCheck: true);
 0473            if (!CanGetSecureStream)
 0474            {
 0475                InnerStream.Write(buffer, offset, count);
 0476                return;
 477            }
 478
 0479            WriteAsync<SyncReadWriteAdapter>(new ReadOnlyMemory<byte>(buffer, offset, count), default(CancellationToken)
 0480        }
 481
 482        /// <returns>A <see cref="Task"/> that represents the asynchronous read operation.</returns>
 483        public override Task WriteAsync(byte[] buffer, int offset, int count, CancellationToken cancellationToken)
 0484        {
 0485            ValidateBufferArguments(buffer, offset, count);
 486
 0487            ThrowIfFailed(authSuccessCheck: true);
 0488            if (!CanGetSecureStream)
 0489            {
 0490                return InnerStream.WriteAsync(buffer, offset, count, cancellationToken);
 491            }
 492
 0493            return WriteAsync<AsyncReadWriteAdapter>(new ReadOnlyMemory<byte>(buffer, offset, count), cancellationToken)
 0494        }
 495
 496        /// <returns>A <see cref="ValueTask"/> that represents the asynchronous read operation.</returns>
 497        public override ValueTask WriteAsync(ReadOnlyMemory<byte> buffer, CancellationToken cancellationToken = default)
 0498        {
 0499            ThrowIfFailed(authSuccessCheck: true);
 0500            if (!CanGetSecureStream)
 0501            {
 0502                return InnerStream.WriteAsync(buffer, cancellationToken);
 503            }
 504
 0505            return new ValueTask(WriteAsync<AsyncReadWriteAdapter>(buffer, cancellationToken));
 0506        }
 507
 508        private async Task WriteAsync<TIOAdapter>(ReadOnlyMemory<byte> buffer, CancellationToken cancellationToken)
 509            where TIOAdapter : IReadWriteAdapter
 0510        {
 0511            Debug.Assert(_context is not null);
 0512            Debug.Assert(_writeBuffer is not null);
 513
 0514            if (Interlocked.Exchange(ref _writeInProgress, true))
 0515            {
 0516                throw new NotSupportedException(SR.Format(SR.net_io_invalidnestedcall, "write"));
 517            }
 518
 519            try
 0520            {
 0521                ThrowIfFailed(authSuccessCheck: true);
 522
 0523                while (!buffer.IsEmpty)
 0524                {
 0525                    int chunkBytes = Math.Min(buffer.Length, MaxWriteDataSize);
 526
 0527                    bool isEncrypted = _context.IsEncrypted;
 528                    NegotiateAuthenticationStatusCode statusCode;
 0529                    ReadOnlyMemory<byte> bufferToWrap = buffer.Slice(0, chunkBytes);
 530
 0531                    if (isNtlm && !isEncrypted)
 0532                    {
 533                        // Non-encrypted NTLM uses an encoding quirk
 0534                        _context.ComputeIntegrityCheck(bufferToWrap.Span, _writeBuffer);
 0535                        _writeBuffer.Write(bufferToWrap.Span);
 0536                        statusCode = NegotiateAuthenticationStatusCode.Completed;
 0537                    }
 538                    else
 0539                    {
 0540                        statusCode = _context.Wrap(bufferToWrap.Span, _writeBuffer, isEncrypted, out _);
 0541                    }
 542
 0543                    if (statusCode != NegotiateAuthenticationStatusCode.Completed)
 0544                    {
 545                        // TODO: Trace the error
 0546                        throw new IOException(SR.net_io_encrypt);
 547                    }
 548
 0549                    BinaryPrimitives.WriteInt32LittleEndian(_writeHeader, _writeBuffer.WrittenCount);
 0550                    await TIOAdapter.WriteAsync(InnerStream, _writeHeader, cancellationToken).ConfigureAwait(false);
 551
 0552                    await TIOAdapter.WriteAsync(InnerStream, _writeBuffer.WrittenMemory, cancellationToken).ConfigureAwa
 0553                    buffer = buffer.Slice(chunkBytes);
 0554                    _writeBuffer.Clear();
 0555                }
 0556            }
 0557            catch (Exception e) when (!(e is IOException || e is OperationCanceledException))
 0558            {
 0559                throw new IOException(SR.net_io_write, e);
 560            }
 561            finally
 0562            {
 0563                _writeBuffer.Clear();
 0564                _writeInProgress = false;
 0565            }
 0566        }
 567
 568        public override IAsyncResult BeginRead(byte[] buffer, int offset, int count, AsyncCallback? asyncCallback, objec
 0569            TaskToAsyncResult.Begin(ReadAsync(buffer, offset, count), asyncCallback, asyncState);
 570
 571        public override int EndRead(IAsyncResult asyncResult) =>
 0572            TaskToAsyncResult.End<int>(asyncResult);
 573
 574        public override IAsyncResult BeginWrite(byte[] buffer, int offset, int count, AsyncCallback? asyncCallback, obje
 0575            TaskToAsyncResult.Begin(WriteAsync(buffer, offset, count), asyncCallback, asyncState);
 576
 577        public override void EndWrite(IAsyncResult asyncResult) =>
 0578            TaskToAsyncResult.End(asyncResult);
 579
 580        private void ThrowIfExceptional()
 0581        {
 0582            ExceptionDispatchInfo? e = _exception;
 0583            if (e != null)
 0584            {
 0585                ThrowExceptional(e);
 0586            }
 587
 588            // Local function to make the check method more inline friendly.
 589            void ThrowExceptional(ExceptionDispatchInfo e)
 0590            {
 591                // If the stored exception just indicates disposal, throw a new ODE rather than the stored one,
 592                // so as to not continually build onto the shared exception's stack.
 0593                ObjectDisposedException.ThrowIf(ReferenceEquals(e, s_disposedSentinel), this);
 594
 595                // Throw the stored exception.
 0596                e.Throw();
 597            }
 0598        }
 599
 600        private void ValidateCreateContext(
 601            string package,
 602            NetworkCredential credential,
 603            string servicePrincipalName,
 604            ExtendedProtectionPolicy? policy,
 605            ProtectionLevel protectionLevel,
 606            TokenImpersonationLevel impersonationLevel)
 0607        {
 0608            if (policy != null)
 0609            {
 610                // One of these must be set if EP is turned on
 0611                if (policy.CustomChannelBinding == null && policy.CustomServiceNames == null)
 0612                {
 0613                    throw new ArgumentException(SR.net_auth_must_specify_extended_protection_scheme, nameof(policy));
 614                }
 615
 0616                _extendedProtectionPolicy = policy;
 0617            }
 618            else
 0619            {
 0620                _extendedProtectionPolicy = new ExtendedProtectionPolicy(PolicyEnforcement.Never);
 0621            }
 622
 0623            ValidateCreateContext(package, isServer: true, credential, servicePrincipalName, _extendedProtectionPolicy.C
 0624        }
 625
 626        private void ValidateCreateContext(
 627            string package,
 628            bool isServer,
 629            NetworkCredential credential,
 630            string? servicePrincipalName,
 631            ChannelBinding? channelBinding,
 632            ProtectionLevel protectionLevel,
 633            TokenImpersonationLevel impersonationLevel)
 0634        {
 0635            if (!_canRetryAuthentication)
 0636            {
 0637                ThrowIfExceptional();
 0638            }
 639
 0640            if (_context != null)
 0641            {
 0642                throw new InvalidOperationException(SR.net_auth_reauth);
 643            }
 644
 0645            ArgumentNullException.ThrowIfNull(credential);
 0646            ArgumentNullException.ThrowIfNull(servicePrincipalName);
 647
 0648            if (impersonationLevel != TokenImpersonationLevel.Identification &&
 0649                impersonationLevel != TokenImpersonationLevel.Impersonation &&
 0650                impersonationLevel != TokenImpersonationLevel.Delegation)
 0651            {
 0652                throw new ArgumentOutOfRangeException(nameof(impersonationLevel), impersonationLevel.ToString(), SR.net_
 653            }
 654
 0655            if (_context is not null && IsServer != isServer)
 0656            {
 0657                throw new InvalidOperationException(SR.net_auth_client_server);
 658            }
 659
 0660            _exception = null;
 0661            _remoteOk = false;
 0662            _framer = new StreamFramer();
 0663            _framer.WriteHeader.MessageId = FrameHeader.HandshakeId;
 664
 0665            _canRetryAuthentication = false;
 666
 667            // A workaround for the client when talking to Win9x on the server side.
 0668            if (protectionLevel == ProtectionLevel.None && !isServer)
 0669            {
 0670                package = NegotiationInfoClass.NTLM;
 0671            }
 672
 0673            if (isServer)
 0674            {
 0675                _expectedProtectionLevel = protectionLevel;
 0676                _expectedImpersonationLevel = impersonationLevel;
 0677                _context = new NegotiateAuthentication(
 0678                    new NegotiateAuthenticationServerOptions
 0679                    {
 0680                        Package = package,
 0681                        Credential = credential,
 0682                        Binding = channelBinding,
 0683                        RequiredProtectionLevel = protectionLevel,
 0684                        RequiredImpersonationLevel = impersonationLevel,
 0685                        Policy = _extendedProtectionPolicy,
 0686                    });
 0687            }
 688            else
 0689            {
 0690                _expectedProtectionLevel = protectionLevel;
 0691                _expectedImpersonationLevel = TokenImpersonationLevel.None;
 0692                _context = new NegotiateAuthentication(
 0693                    new NegotiateAuthenticationClientOptions
 0694                    {
 0695                        Package = package,
 0696                        Credential = credential,
 0697                        TargetName = servicePrincipalName,
 0698                        Binding = channelBinding,
 0699                        RequiredProtectionLevel = protectionLevel,
 0700                        AllowedImpersonationLevel = impersonationLevel,
 0701                        RequireMutualAuthentication = protectionLevel != ProtectionLevel.None
 0702                    },
 0703                    enforceMutualAuthentication: false);
 0704            }
 0705        }
 706
 707        private void SetFailed(Exception e)
 0708        {
 0709            if (_exception == null || !(_exception.SourceException is ObjectDisposedException))
 0710            {
 0711                _exception = ExceptionDispatchInfo.Capture(e);
 0712            }
 713
 0714            _context?.Dispose();
 0715        }
 716
 717        private void ThrowIfFailed(bool authSuccessCheck)
 0718        {
 0719            ThrowIfExceptional();
 720
 0721            if (authSuccessCheck && !IsAuthenticatedCore)
 0722            {
 0723                throw new InvalidOperationException(SR.net_auth_noauth);
 724            }
 0725        }
 726
 727        private async Task AuthenticateAsync<TIOAdapter>(CancellationToken cancellationToken)
 728            where TIOAdapter : IReadWriteAdapter
 0729        {
 0730            Debug.Assert(_context != null);
 731
 0732            ThrowIfFailed(authSuccessCheck: false);
 0733            if (Interlocked.Exchange(ref _authInProgress, true))
 0734            {
 0735                throw new InvalidOperationException(SR.Format(SR.net_io_invalidnestedcall, "authenticate"));
 736            }
 737
 738            try
 0739            {
 0740                await (_context.IsServer ?
 0741                    ReceiveBlobAsync<TIOAdapter>(cancellationToken) : // server should listen for a client blob
 0742                    SendBlobAsync<TIOAdapter>(message: null, cancellationToken)).ConfigureAwait(false); // client should
 0743            }
 0744            catch (Exception e)
 0745            {
 0746                SetFailed(e);
 0747                throw;
 748            }
 749            finally
 0750            {
 0751                _authInProgress = false;
 0752            }
 0753        }
 754
 755        // Client authentication starts here, but server also loops through this method.
 756        private async Task SendBlobAsync<TIOAdapter>(byte[]? message, CancellationToken cancellationToken)
 757            where TIOAdapter : IReadWriteAdapter
 0758        {
 0759            Debug.Assert(_context != null);
 760
 0761            NegotiateAuthenticationStatusCode statusCode = NegotiateAuthenticationStatusCode.Completed;
 0762            if (message != s_emptyMessage)
 0763            {
 0764                message = _context.GetOutgoingBlob(message, out statusCode);
 0765            }
 766
 0767            if (statusCode is NegotiateAuthenticationStatusCode.BadBinding or
 0768                NegotiateAuthenticationStatusCode.TargetUnknown or
 0769                NegotiateAuthenticationStatusCode.ImpersonationValidationFailed or
 0770                NegotiateAuthenticationStatusCode.SecurityQosFailed)
 0771            {
 0772                Exception exception = statusCode switch
 0773                {
 0774                    NegotiateAuthenticationStatusCode.BadBinding =>
 0775                        new AuthenticationException(SR.net_auth_bad_client_creds_or_target_mismatch),
 0776                    NegotiateAuthenticationStatusCode.TargetUnknown =>
 0777                        new AuthenticationException(SR.net_auth_bad_client_creds_or_target_mismatch),
 0778                    NegotiateAuthenticationStatusCode.ImpersonationValidationFailed =>
 0779                        new AuthenticationException(SR.Format(SR.net_auth_context_expectation, _expectedImpersonationLev
 0780                    _ => // NegotiateAuthenticationStatusCode.SecurityQosFailed
 0781                        new AuthenticationException(SR.Format(SR.net_auth_context_expectation, _context.ProtectionLevel.
 0782                };
 783
 0784                message = new byte[sizeof(long)];
 0785                BinaryPrimitives.WriteInt64LittleEndian(message, ERROR_TRUST_FAILURE);
 786
 0787                await SendAuthResetSignalAndThrowAsync<TIOAdapter>(message, exception, cancellationToken).ConfigureAwait
 0788                Debug.Fail("Unreachable");
 789            }
 0790            else if (statusCode == NegotiateAuthenticationStatusCode.Completed)
 0791            {
 0792                _writeBuffer = new ArrayBufferWriter<byte>();
 793
 0794                isNtlm = string.Equals(_context.Package, NegotiationInfoClass.NTLM);
 795
 796                // Signal remote party that we are done
 0797                _framer!.WriteHeader.MessageId = FrameHeader.HandshakeDoneId;
 0798                if (_context.IsServer)
 0799                {
 800                    // Server may complete now because client SSPI would not complain at this point.
 0801                    _remoteOk = true;
 802
 803                    // However the client will wait for server to send this ACK
 804                    // Force signaling server OK to the client
 0805                    message ??= s_emptyMessage;
 0806                }
 807
 0808                if (message != null)
 0809                {
 810                    //even if we are completed, there could be a blob for sending.
 0811                    await _framer!.WriteMessageAsync<TIOAdapter>(InnerStream, message, cancellationToken).ConfigureAwait
 0812                }
 813
 0814                if (_remoteOk)
 0815                {
 816                    // We are done with success.
 0817                    return;
 818                }
 0819            }
 0820            else if (statusCode != NegotiateAuthenticationStatusCode.ContinueNeeded)
 0821            {
 0822                int errorCode = statusCode switch
 0823                {
 0824                    NegotiateAuthenticationStatusCode.BadBinding => (int)Interop.SECURITY_STATUS.BadBinding,
 0825                    NegotiateAuthenticationStatusCode.Unsupported => (int)Interop.SECURITY_STATUS.Unsupported,
 0826                    NegotiateAuthenticationStatusCode.MessageAltered => (int)Interop.SECURITY_STATUS.MessageAltered,
 0827                    NegotiateAuthenticationStatusCode.ContextExpired => (int)Interop.SECURITY_STATUS.ContextExpired,
 0828                    NegotiateAuthenticationStatusCode.CredentialsExpired => (int)Interop.SECURITY_STATUS.CertExpired,
 0829                    NegotiateAuthenticationStatusCode.InvalidCredentials => (int)Interop.SECURITY_STATUS.LogonDenied,
 0830                    NegotiateAuthenticationStatusCode.InvalidToken => (int)Interop.SECURITY_STATUS.InvalidToken,
 0831                    NegotiateAuthenticationStatusCode.UnknownCredentials => (int)Interop.SECURITY_STATUS.UnknownCredenti
 0832                    NegotiateAuthenticationStatusCode.QopNotSupported => (int)Interop.SECURITY_STATUS.QopNotSupported,
 0833                    NegotiateAuthenticationStatusCode.OutOfSequence => (int)Interop.SECURITY_STATUS.OutOfSequence,
 0834                    _ => (int)Interop.SECURITY_STATUS.InternalError
 0835                };
 0836                Win32Exception win32Exception = new Win32Exception(errorCode);
 0837                Exception exception = statusCode switch
 0838                {
 0839                    NegotiateAuthenticationStatusCode.InvalidCredentials =>
 0840                        new InvalidCredentialException(IsServer ? SR.net_auth_bad_client_creds : SR.net_auth_bad_client_
 0841                    _ => new AuthenticationException(SR.net_auth_SSPI, win32Exception)
 0842                };
 843
 0844                message = new byte[sizeof(long)];
 0845                BinaryPrimitives.WriteInt64LittleEndian(message, errorCode);
 846
 847                // Signal remote side on a failed attempt.
 0848                await SendAuthResetSignalAndThrowAsync<TIOAdapter>(message!, exception, cancellationToken).ConfigureAwai
 0849                Debug.Fail("Unreachable");
 850            }
 851            else
 0852            {
 0853                if (message == null || message == s_emptyMessage)
 0854                {
 0855                    throw new InternalException();
 856                }
 857
 0858                await _framer!.WriteMessageAsync<TIOAdapter>(InnerStream, message, cancellationToken).ConfigureAwait(fal
 0859            }
 860
 0861            await ReceiveBlobAsync<TIOAdapter>(cancellationToken).ConfigureAwait(false);
 0862        }
 863
 864        // Server authentication starts here, but client also loops through this method.
 865        private async Task ReceiveBlobAsync<TIOAdapter>(CancellationToken cancellationToken)
 866            where TIOAdapter : IReadWriteAdapter
 0867        {
 0868            Debug.Assert(_framer != null);
 869
 0870            byte[]? message = await _framer.ReadMessageAsync<TIOAdapter>(InnerStream, cancellationToken).ConfigureAwait(
 0871            if (message == null)
 0872            {
 873                // This is an EOF otherwise we would get at least *empty* message but not a null one.
 0874                throw new AuthenticationException(SR.net_auth_eof);
 875            }
 876
 877            // Process Header information.
 0878            if (_framer.ReadHeader.MessageId == FrameHeader.HandshakeErrId)
 0879            {
 0880                if (message.Length >= sizeof(long))
 0881                {
 882                    // Try to recover remote win32 Exception.
 0883                    long error = BinaryPrimitives.ReadInt64LittleEndian(message);
 0884                    ThrowCredentialException(error);
 0885                }
 886
 0887                throw new AuthenticationException(SR.net_auth_alert);
 888            }
 889
 0890            if (_framer.ReadHeader.MessageId == FrameHeader.HandshakeDoneId)
 0891            {
 0892                if (HandshakeComplete && message.Length > 0)
 0893                {
 0894                    Debug.Assert(_context != null);
 0895                    _context.GetOutgoingBlob(message, out NegotiateAuthenticationStatusCode statusCode);
 0896                    _remoteOk = statusCode is NegotiateAuthenticationStatusCode.Completed;
 0897                }
 898                else
 0899                {
 0900                    _remoteOk = true;
 0901                }
 0902            }
 0903            else if (_framer.ReadHeader.MessageId != FrameHeader.HandshakeId)
 0904            {
 0905                throw new AuthenticationException(SR.Format(SR.net_io_header_id, nameof(FrameHeader.MessageId), _framer.
 906            }
 907
 908            // If we are done don't go into send.
 0909            if (HandshakeComplete)
 0910            {
 0911                if (!_remoteOk)
 0912                {
 0913                    throw new AuthenticationException(SR.Format(SR.net_io_header_id, nameof(FrameHeader.MessageId), _fra
 914                }
 915
 0916                return;
 917            }
 918
 919            // Not yet done, get a new blob and send it if any.
 0920            await SendBlobAsync<TIOAdapter>(message, cancellationToken).ConfigureAwait(false);
 0921        }
 922
 923        //  This is to reset auth state on the remote side.
 924        //  If this write succeeds we will allow auth retrying.
 925        private async Task SendAuthResetSignalAndThrowAsync<TIOAdapter>(byte[] message, Exception exception, Cancellatio
 926            where TIOAdapter : IReadWriteAdapter
 0927        {
 0928            _framer!.WriteHeader.MessageId = FrameHeader.HandshakeErrId;
 929
 0930            await _framer.WriteMessageAsync<TIOAdapter>(InnerStream, message, cancellationToken).ConfigureAwait(false);
 931
 0932            _canRetryAuthentication = true;
 0933            ExceptionDispatchInfo.Throw(exception);
 934        }
 935
 936        private static void ThrowCredentialException(long error)
 0937        {
 0938            var e = new Win32Exception((int)error);
 0939            throw e.NativeErrorCode switch
 0940            {
 0941                // Compatibility quirk: .NET Core and .NET 5/6 incorrectly report internal status code instead of Win32 
 0942                (int)SecurityStatusPalErrorCode.LogonDenied => new InvalidCredentialException(SR.net_auth_bad_client_cre
 0943                (int)Interop.SECURITY_STATUS.LogonDenied => new InvalidCredentialException(SR.net_auth_bad_client_creds,
 0944                ERROR_TRUST_FAILURE => new AuthenticationException(SR.net_auth_context_expectation_remote, e),
 0945                _ => new AuthenticationException(SR.net_auth_alert, e)
 0946            };
 947        }
 948    }
 949}
 950

Methods/Properties

.cctor()
.ctor(System.IO.Stream)
.ctor(System.IO.Stream,System.Boolean)
Dispose(System.Boolean)
DisposeAsync()
BeginAuthenticateAsClient(System.AsyncCallback,System.Object)
BeginAuthenticateAsClient(System.Net.NetworkCredential,System.String,System.AsyncCallback,System.Object)
BeginAuthenticateAsClient(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ChannelBinding,System.String,System.AsyncCallback,System.Object)
BeginAuthenticateAsClient(System.Net.NetworkCredential,System.String,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel,System.AsyncCallback,System.Object)
BeginAuthenticateAsClient(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ChannelBinding,System.String,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel,System.AsyncCallback,System.Object)
EndAuthenticateAsClient(System.IAsyncResult)
AuthenticateAsServer()
AuthenticateAsServer(System.Security.Authentication.ExtendedProtection.ExtendedProtectionPolicy)
AuthenticateAsServer(System.Net.NetworkCredential,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
AuthenticateAsServer(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ExtendedProtectionPolicy,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
BeginAuthenticateAsServer(System.AsyncCallback,System.Object)
BeginAuthenticateAsServer(System.Security.Authentication.ExtendedProtection.ExtendedProtectionPolicy,System.AsyncCallback,System.Object)
BeginAuthenticateAsServer(System.Net.NetworkCredential,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel,System.AsyncCallback,System.Object)
BeginAuthenticateAsServer(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ExtendedProtectionPolicy,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel,System.AsyncCallback,System.Object)
EndAuthenticateAsServer(System.IAsyncResult)
AuthenticateAsClient()
AuthenticateAsClient(System.Net.NetworkCredential,System.String)
AuthenticateAsClient(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ChannelBinding,System.String)
AuthenticateAsClient(System.Net.NetworkCredential,System.String,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
AuthenticateAsClient(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ChannelBinding,System.String,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
AuthenticateAsClientAsync()
AuthenticateAsClientAsync(System.Net.NetworkCredential,System.String)
AuthenticateAsClientAsync(System.Net.NetworkCredential,System.String,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
AuthenticateAsClientAsync(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ChannelBinding,System.String)
AuthenticateAsClientAsync(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ChannelBinding,System.String,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
AuthenticateAsServerAsync()
AuthenticateAsServerAsync(System.Security.Authentication.ExtendedProtection.ExtendedProtectionPolicy)
AuthenticateAsServerAsync(System.Net.NetworkCredential,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
AuthenticateAsServerAsync(System.Net.NetworkCredential,System.Security.Authentication.ExtendedProtection.ExtendedProtectionPolicy,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
IsAuthenticated()
IsAuthenticatedCore()
IsMutuallyAuthenticated()
IsEncrypted()
IsSigned()
IsServer()
ImpersonationLevel()
PrivateImpersonationLevel()
HandshakeComplete()
CanGetSecureStream()
RemoteIdentity()
CanSeek()
CanRead()
CanTimeout()
CanWrite()
ReadTimeout()
ReadTimeout(System.Int32)
WriteTimeout()
WriteTimeout(System.Int32)
Length()
Position()
Position(System.Int64)
SetLength(System.Int64)
Seek(System.Int64,System.IO.SeekOrigin)
Flush()
FlushAsync(System.Threading.CancellationToken)
Read(System.Byte[],System.Int32,System.Int32)
ReadAsync(System.Byte[],System.Int32,System.Int32,System.Threading.CancellationToken)
ReadAsync(System.Memory`1<System.Byte>,System.Threading.CancellationToken)
ReadAllAsync(System.IO.Stream,System.Memory`1<System.Byte>,System.Boolean,System.Threading.CancellationToken)
Write(System.Byte[],System.Int32,System.Int32)
WriteAsync(System.Byte[],System.Int32,System.Int32,System.Threading.CancellationToken)
WriteAsync(System.ReadOnlyMemory`1<System.Byte>,System.Threading.CancellationToken)
WriteAsync(System.ReadOnlyMemory`1<System.Byte>,System.Threading.CancellationToken)
BeginRead(System.Byte[],System.Int32,System.Int32,System.AsyncCallback,System.Object)
EndRead(System.IAsyncResult)
BeginWrite(System.Byte[],System.Int32,System.Int32,System.AsyncCallback,System.Object)
EndWrite(System.IAsyncResult)
ThrowIfExceptional()
ThrowExceptional(System.Runtime.ExceptionServices.ExceptionDispatchInfo)
ValidateCreateContext(System.String,System.Net.NetworkCredential,System.String,System.Security.Authentication.ExtendedProtection.ExtendedProtectionPolicy,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
ValidateCreateContext(System.String,System.Boolean,System.Net.NetworkCredential,System.String,System.Security.Authentication.ExtendedProtection.ChannelBinding,System.Net.Security.ProtectionLevel,System.Security.Principal.TokenImpersonationLevel)
SetFailed(System.Exception)
ThrowIfFailed(System.Boolean)
AuthenticateAsync(System.Threading.CancellationToken)
SendBlobAsync(System.Byte[],System.Threading.CancellationToken)
ReceiveBlobAsync(System.Threading.CancellationToken)
SendAuthResetSignalAndThrowAsync(System.Byte[],System.Exception,System.Threading.CancellationToken)
ThrowCredentialException(System.Int64)