Provision to a Microsoft Azure Application Gateway
Focus
Focus
Next‑Gen Trust Security

Provision to a Microsoft Azure Application Gateway

Table of Contents

Provision to a Microsoft Azure Application Gateway

Use this procedure to provision a certificate from Next-Gen Trust Security to a Microsoft Azure Application Gateway machine.
  1. Sign in to Next-Gen Trust Security.
  2. Click Insights > Certificate Installations > Machines.
  3. Select the Microsoft Azure Application Gateway machine where you want to install the certificate.
  4. Click Provision a certificate.
  5. From Choose a certificate from the inventory, search for and select the certificate you want to provision.
    Verify that you selected the correct certificate by reviewing the Subject DN, Validity, and Fingerprint.
  6. In Resource Group, enter the resource group that contains the target Application Gateway.
  7. In Application Gateway Name, enter the name of the target Application Gateway.
  8. In Certificate Name, enter the name of the SSL certificate on the Application Gateway.
    Note: If a certificate with this name already exists on the gateway, Next-Gen Trust Security replaces its contents. If no certificate with this name exists, Next-Gen Trust Security adds one. An Application Gateway supports a maximum of 100 SSL certificates.
  9. In Listener Name, enter the name of the HTTPS listener that the SSL certificate is bound to.
    Important: The listener must already exist on the Application Gateway. Provisioning fails if the named listener is not found.
  10. (Optional) To prevent the certificate from being pushed immediately, set Push upon saving to No.
  11. Click Save.
After saving, Next-Gen Trust Security provisions the certificate to the specified Application Gateway, binds it to the listener, and creates an installation record on the Certificate Installations tab.
Note: Azure applies certificate changes to an Application Gateway as a long-running operation that can take several minutes to complete. Because only one such operation can run on a gateway at a time, Next-Gen Trust Security waits and retries if another change is already in progress. Avoid provisioning several certificates to the same Application Gateway at once.
Note: If the gateway already holds the same certificate and the listener already references it, Next-Gen Trust Security reports success without changing the gateway.