Deploy certificates by using Azure Key Vault. Certificate auto-rotation in Key Vault

Sharing is caring!

&NewLine;<p>The certificates can be public and private Secure Sockets Layer &lpar;SSL&rpar;&sol;Transport Layer Security &lpar;TLS&rpar; certificates signed by a certificate authority &lpar;CA&rpar;&comma; or a self-signed certificate&period; Key Vault can also request and renew certificates through partnerships with CAs&comma; providing a robust solution for certificate lifecycle management&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">&NewLine;<figure class&equals;"wp-block-image size-large wp-duotone-3355dd-ffffff-1"><img data-id&equals;"853" src&equals;"https&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2022&sol;12&sol;certificate-authority-2&period;png" alt&equals;"" class&equals;"wp-image-853"&sol;><&sol;figure>&NewLine;<&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>A certificate created in Key Vault can be&colon;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>A self-signed certificate&period;<&sol;li><li>A certificate created with a CA that&&num;8217&semi;s partnered with Key Vault&period;<&sol;li><li>A certificate with a CA that isn&&num;8217&semi;t partnered with Key Vault&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>The following CAs are currently partnered providers with Key Vault&colon;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>DigiCert&colon; Key Vault offers OV TLS&sol;SSL certificates&period;<&sol;li><li>GlobalSign&colon; Key Vault offers OV TLS&sol;SSL certificates&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"has-primary-color has-text-color">Key Vault auto-rotates certificates through established partnerships with CAs&period; Because Key Vault automatically requests and renews certificates through the partnership&comma; auto-rotation capability is not applicable for certificates created with CAs that are not partnered with Key Vault&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>We can<&sol;strong> <strong>create a certificate with a known issuer provider&colon;<&sol;strong>&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure Key Vault allows you to easily provision&comma; manage&comma; and deploy digital certificates for your network and to enable secure communications for applications&period; A digital certificate is an electronic credential that establishes proof of identity in an electronic transaction&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure Key Vault has a trusted partnership with the following Certificate Authorities&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li><a href&equals;"https&colon;&sol;&sol;www&period;digicert&period;com&sol;">DigiCert<&sol;a><&sol;li><li><a href&equals;"https&colon;&sol;&sol;www&period;globalsign&period;com&sol;en">GlobalSign<&sol;a><&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure Key Vault users can generate DigiCert&sol;GlobalSign certificates directly from their key vaults&period; Key Vault&&num;8217&semi;s partnership ensures end-to-end certificate lifecycle management for certificates issued by DigiCert&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>How to add GlobalSign certificate authority<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ol class&equals;"wp-block-list"><li>To add GlobalSign certificate authority&comma; go to the key vault you want to add it to&period;<&sol;li><li>On the Key Vault property page&comma; select&nbsp&semi;<strong>Certificates<&sol;strong>&period;<&sol;li><li>Select the&nbsp&semi;<strong>Certificate Authorities<&sol;strong>&nbsp&semi;tab&colon;&nbsp&semi;<&sol;li><&sol;ol>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image size-large"><img src&equals;"https&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2022&sol;12&sol;select-certificate-authorities-1024x250&period;png" alt&equals;"" class&equals;"wp-image-854"&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading" id&equals;"update-certificate-lifecycle-attributes-at-the-time-of-creation">Update certificate lifecycle attributes to renew certificate automatically<&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure Key Vault handles the end-to-end maintenance of certificates that are issued by trusted Microsoft certificate authorities DigiCert and GlobalSign&period;&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li><strong>Validity Period<&sol;strong>&colon; Enter the value &lpar;in months&rpar;&period; Creating short-lived certificates is a recommended security practice&period; By default&comma; the validity value of a newly created certificate is 12 months&period;<&sol;li><li><strong>Lifetime Action Type<&sol;strong>&colon; Select the certificate&&num;8217&semi;s auto-renewal and alerting action and then update&nbsp&semi;<strong>percentage lifetime<&sol;strong>&nbsp&semi;or&nbsp&semi;<strong>Number of days before expiry<&sol;strong>&period; By default&comma; a certificate&&num;8217&semi;s auto-renewal is set at 80 percent of its lifetime&period;&nbsp&semi;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-table"><table><thead><tr><th>Automatically renew at a given time<&sol;th><th>Email all contacts at a given time<&sol;th><&sol;tr><&sol;thead><tbody><tr><td>Selecting this option will&nbsp&semi;<em>turn on<&sol;em>&nbsp&semi;autorotation&period;<&sol;td><td>Selecting this option will&nbsp&semi;<em>not<&sol;em>&nbsp&semi;auto-rotate but will only alert the contacts&period;<&sol;td><&sol;tr><&sol;tbody><&sol;table><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading" id&equals;"get-notified-about-certificate-expiration">Get notified about certificate expiration<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<p>To get notified about certificate life events&comma; you would need to add certificate contact&period; Certificate contacts contain contact information to send notifications triggered by certificate lifetime events&period; The contacts information is shared by all the certificates in the key vault&period; A notification is sent to all the specified contacts for an event for any certificate in the key vault&period;<&sol;p>&NewLine;