Skip to content

Azure API Management

  1. In the Certificate Manager - SaaS toolbar, click Machines.
  2. Click the name of your Azure API Management machine.
  3. In the machine drawer, click Installations.
  4. Click Provision.
  5. In the Search a certificate by name, expiration or fingerprint field, begin typing the certificate name you want to provision. Click the certificate when you see it listed.

    Verify that you've selected the correct certificate by reviewing the Subject DN, Validity, and Fingerprint.

    Note

    Only Certificate Manager - SaaS-generated and user-imported certificates with private keys can be provisioned. The certificate's common name (CN) or subject alternative name (SAN) must match the custom domain hostname you specify in the next step.

  6. In the Hostname field, enter the hostname of the Azure API Management custom domain where you want to install the certificate (for example, api.example.com).

  7. From the Domain Type drop-down, select the type of custom domain endpoint:

    • Gateway – The primary API gateway endpoint (default)
    • Developer Portal – The developer portal endpoint
    • Management – The management API endpoint
    • Source Control (SCM) – The source control management endpoint
    • Configuration API – The configuration API endpoint
  8. From the Certificate Source drop-down, select Custom (Uploaded).

    Note

    If a custom domain is already configured with a certificate from Azure Key Vault, provisioning to that hostname replaces the Key Vault reference with the uploaded (Custom) certificate. Key Vault-backed certificates on other (non-targeted) domains are flagged during discovery and left unchanged.

  9. (Optional) In the Description field, you can optionally enter a machine installation description.

  10. If you don't want the certificate to be pushed when you save, toggle the Push upon saving slider to No.

  11. Click Save.

    Want to schedule your provisions?

    Schedule your provisions daily, weekly, or monthly. Learn more

After saving, the certificate is converted to Azure's required format and submitted to the specified custom domain. The connector reports success once Azure accepts the update. The certificate installation completes asynchronously. All other custom domains on the same API Management instance are preserved.