An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
Application Gateway: Certificate Serving Issue for Specific SNI Hostname — Investigation and Potential Cause
Problem description
I am experiencing an issue where my Application Gateway is serving the wrong SSL certificate for a specific SNI hostname. This problem persists even after stop/start, redeployments, and capacity adjustments. Other hostnames on the same gateway function correctly, but this particular hostname consistently receives an incorrect certificate.
Environment
Azure Application Gateway, specific hostname, region not specified.
What I've already tried
I reviewed the available case details and diagnostic information. I exported the listener, frontend IP, port, and SSL certificate objects via CLI. I compared the failing listener with a working one, noting they share the same etag and frontend configuration but differ in hostname and SSL certificate reference. I also validated that the affected listener is bound to the intended frontend IP and port, with the correct hostname and certificate. Additionally, I performed certificate validation using openssl, confirming that the served certificate's fingerprint matches the one configured in the listener. Despite these checks, the issue persists.
Current status
I suspect a potential certificate-binding or lookup bug within the Application Gateway's SNI resolution process for this particular listener. I am seeking guidance on diagnostic data that could help confirm this hypothesis or alternative solutions to resolve this certificate serving issue.