Azure AD Application Proxy SSL Certificate for custom domain

Andy Harris 21 Reputation points
2022-02-07T14:58:44.133+00:00

We created an AAP app with a custom domain a little while ago and applied our wildcard certificate without issue.

We've recently added several other AAP apps and configured them in exactly the same way using the same certificate, however each of these is presenting a *.msappproxy.net certificate when you visit the custom domain name, causing browsers to report it as insecure with a NET::ERR_CERT_COMMON_NAME_INVALID error.

I see someone else experienced the same issue here and someone from MS fixed it for them: https://learn.microsoft.com/en-us/answers/questions/170336/azure-ad-application-proxy-ssl-certificate-for-cus.html - Could somebody take a look please?

Many thanks,
Andy

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

Accepted answer
  1. Siva-kumar-selvaraj 15,721 Reputation points
    2022-03-02T08:00:14.62+00:00

    Hello @Andy Harris ,

    The issue has been resolved after re-upload the SSL certificate. Therefore, sharing it here which may be useful to other members of the community reading this topic.

    -----
    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


1 additional answer

Sort by: Most helpful
  1. Andy Harris 21 Reputation points
    2022-03-02T10:08:56.123+00:00

    As mentioned by @sikumars-msft, it appears there is currently an issue when re-using an existing SSL certificate for new apps, in that the certificate doesn't get applied is it should.

    The current workaround is to re-upload the SSL certificate for each app you're seeing a certificate issue with.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.