-
Hi, We are having difficulties with some application (not build by our selfes) that cannot connect to the Application Gateway investigating this issue using SSLlabs for example do indeed show that the order is incorrect indeed The certificates are LetsEncrypt issued using this awesome keyvault-acmebot and stored in keyvault Using a browser for testing does not show that the order is incorrect and accepts it as it is, as long that it is complete We opened a support case at Microsoft to see if we can fix the issue, unfortunatly they only have a tool that manipulates the cert to correct the order in keyvault. this is a manual process, as you would understand this is not a viable sollution in a fully automated system. TL;DR: |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 15 replies
-
Is the Application Gateway v1 or v2? I tried to create a v2 environment, but I can't seem to reproduce it. |
Beta Was this translation helpful? Give feedback.
-
Hi, I'm seeing a similar issue after attempting to renew certificates today. Java wasn't happy with the order in the certificate file. I downloaded the currently working PFX and used OpenSSL to convert the working crt file. It has: Private Key When I download the PFX from the new cert and use OpenSSL to convert it I got; Private Key Java would accept the new cert as valid if I swapped the two CA Certs round. We are using the latest.zip so we should have the fix outlined above. Could there be another issue? Neil. |
Beta Was this translation helpful? Give feedback.
-
Hi, I'm facing the exact same problem. I My case: |
Beta Was this translation helpful? Give feedback.
Is the Application Gateway v1 or v2? I tried to create a v2 environment, but I can't seem to reproduce it.