Azure Front Door Designer - 更新自定义域 - 新 SSL
我在 Key Vault 中续订了通配符 SSL 证书,并且在设计器中将秘密版本设置为“最新”,但网站上显示的 SSL 仍然是旧证书。我在 Key Vault 中将过期的 SSL 证书设置为禁用。
如何让 Front Door 识别最新的 SSL 证书?我是否只需要更改一个值(例如最低 TLS 版本)即可触发更新,以便它获取新证书?
有想法吗?
I renewed my Wildcard SSL certificate in my Key Vault and the secret version is set to 'latest' in the desginer, but the the SSL showing on the website is still the old cert. I set the expiring SSL cert to disabled in Key Vault.
How do I get Front Door to recognize the latest SSL cert? Do I just need to change a value, say minimum TLS version, to trigger the update so it picks up the new cert?
Ideas?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
我也面临着这个问题。看来,如果您使用新的 TLS 证书更新 KeyVault 并将 FrontDoor 设置为使用“最新”版本,那么它将在 24 小时内自动神奇地更新。我假设 FrontDoor 有一个流程,每天扫描一次您的 KeyVault 机密并提取最新版本。
或者,为了更直接的控制,您可以将 FrontDoor 设置为使用特定的秘密版本,并在更新 KeyVault 后在 FrontDoor 中手动更新该版本。
这是我找到的小文档的链接: https://learn.microsoft.com/en-us/azure/frontdoor/standard-premium/how-to-configure-https-custom-domain#certificate-renewal-and-changing-certificate-types
I was faced with this as well. It appears that if you update the KeyVault with the new TLS cert and have FrontDoor setup to use the "Latest" version then it will auto-magically update within 24 hrs. I'm assuming FrontDoor has a process that scans your KeyVault secret once a day and pulls the latest version.
Alternatively for more direct control you can set FrontDoor to use a specific secret version and manually update that version in FrontDoor after you've updated KeyVault.
Here's a link to the little documentation I found: https://learn.microsoft.com/en-us/azure/frontdoor/standard-premium/how-to-configure-https-custom-domain#certificate-renewal-and-changing-certificate-types
我能够通过更新“更新自定义域”表单中的 TLS 值来获取要显示的新证书。我的想法是更新表单,这样它就会强制刷新 SSL 证书,这很有效。不理想,但它有效。
I was able to get the new certificate to show by updating the TLS value in the Update Custom Domain form. My thought was to get the form to update so it would force a refresh of the SSL certificate and that worked. Not ideal, but it worked.