How do I create the TLS Certificate for the Azure Premium firewall with the "CA" flage true. This is needed for the TLS inspection.

Steven Davis 21 Reputation points
2022-10-31T19:52:45.42+00:00

Hello all.
I have been suffering for weeks now. In Azure Premium firewall, I want t enable TLS inspection. That requires a Certificate I the key vault. That certificate has special requirements with the most complicated being "CA" = true. This value would indicate I am a certificate authority and no vendor will do this. I have talked with Digicert and Godaddy, along with four others.
So how do I enable TLS inspection and have an internal certificate that can be installed on all the VM's?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
566 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Christian Nicholls 0 Reputation points
    2023-10-05T07:58:43.78+00:00

    For anyone else stumbling into this, I found this blog post a LOT more helpful than the official docs which I found rather esoteric on specifics:

    https://hovermind.com/azure-firewall/tls-inspection.html

    0 comments No comments