A company is migrating its legacy applications to Azure App Service. These applications require client certificates for mutual TLS authentication to backend systems. The security team mandates that these client certificates must be securely stored, automatically renewed, and seamlessly presented by the App Service to the backend systems without requiring manual intervention from developers. Which Azure service combination should be used to manage and deploy these client certificates?
- AImplement Azure Front Door with client certificate authentication.
- BStore client certificates in Azure Key Vault and configure App Service to load them from Key Vault.
- CUse Azure Application Gateway to handle client certificate authentication.
- DUpload client certificates directly to App Service and manually manage renewals.
Show answer & explanationAnswer & explanation
Correct answer: B. Store client certificates in Azure Key Vault and configure App Service to load them from Key Vault.
Storing client certificates in Azure Key Vault allows for secure storage, versioning, and automated renewal (if integrated with a CA). App Service can then be configured to seamlessly load these certificates from Key Vault, presenting them to backend systems for mutual TLS authentication. This approach centralizes certificate management, automates renewals, and eliminates manual intervention, meeting all requirements.
Why the other options are wrong
- A. Azure Front Door also handles *inbound* client certificate authentication (client to Front Door) but does not provide client certificate management for App Service's *outbound* backend calls.
- C. Azure Application Gateway can handle *inbound* client certificate authentication (client to gateway) but is not designed to manage *outbound* client certificates for App Service to backend systems.
- D. Direct upload requires manual renewal management and does not provide centralized, secure storage or automated workflows.
App Service Client Certificates with Key Vault
A secure method for Azure App Service to use client certificates for mutual TLS authentication to backend systems, leveraging Azure Key Vault for certificate storage, management, and automated loading.
- Key Vault securely stores and manages certificates.
- App Service can load certificates directly from Key Vault.
- Supports automated certificate renewal and rotation.
Memory trick: Key Vault: The secure 'pocket' for App Service's outbound certificates.