Aidan Finn 6/16/2026

Windows Lies Make Application Gateway Certs Harder

Read Original

This article details a common issue where Azure Application Gateway's backend health probe fails despite a certificate appearing valid on a Windows server. It explains that Windows silently fills in missing intermediate certificates using the local machine store or AIA chasing, masking incomplete certificate chains. When Application Gateway, acting as a reverse proxy, validates the backend's TLS handshake using OpenSSL-like behavior, it fails because it does not perform these fallbacks. The article covers the technical differences between Windows and Linux/OpenSSL certificate validation, the architecture of Application Gateway as a Layer 7 proxy, and why this leads to red health probes. It is relevant to IT/technology professionals working with Azure, TLS certificates, and web infrastructure.

Windows Lies Make Application Gateway Certs Harder

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet