**Reminder** Azure TLS certificate changes

bharathn-msft 5,086 Reputation points Microsoft Employee
2020-10-06T00:42:59.357+00:00

Hello Azure Customers in the community,

For users that implement certificate pinning in their application code there are some Azure TLS certificate changes that could impact some of our customers. Microsoft is updating Azure services to use TLS certificates from a different set of Root Certificate Authorities (CAs). This change is being made because the current CA certificates do not comply with one of the CA/Browser Forum Baseline requirements. We expect that most Azure customers will not be impacted. However, your application may be impacted if it explicitly specifies a list of acceptable CAs. To learn more please click here.

For any other further help, please reach out to our Support team via Azure portal. Thank you

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,420 questions
{count} votes

21 answers

Sort by: Most helpful
  1. chirag sharma 1 Reputation point
    2020-10-13T06:59:50.937+00:00

    We use Cloudflare as our Certificate Authority.

    Will we need to make any changes or updates in our certificates/app services?

    Thanks In Advance


  2. Henry Zaragoza Jr 1 Reputation point
    2020-10-13T07:28:32.497+00:00

    Hello @bharathn-msft , I am new to Azure. I would like to ask/know if these changes will affect the application insights that we are using in azure? Thank you in advance


  3. Girish Prajwal 706 Reputation points
    2020-10-13T14:15:57.907+00:00

    Hi @bharathn-msft ,

    We received similar alert today, and I verified that both our WebApps and IOT services are not using any certificates. However, we have multiple storage accounts in our subscriptions. How can I identify which storage or the Azure service will be impacted?

    Give me insights.

    Along with this, I am unsure how did my friend received this alert and not me. Is it because the certificates were raised by him using our on-premise Root CA.

    How can I check "How did he receive this alert from Microsoft" if this was an alert set in Azure.

    Regards,

    Girish Prajwal


  4. Vipin Nair 1 Reputation point
    2020-10-13T15:08:46.397+00:00

    I got a email from MS for Review your Azure Services Certificate Authorities.
    We have integrated few applications with Azure AD as Enterprise application for SSO. Are those application impacted?


  5. Jung Choi 27 Reputation points
    2020-10-13T15:11:58.413+00:00

    If you are simply running VMs with Azure, are those services impacted?

    I do have public facing IPs that serve up our application via the VMs but not using the App services.

    How are these impacted?