send-request fails with remote certificate rejected on Standard v2

Itzhaki, Shahar 0 Reputation points
2026-07-14T15:49:19.1966667+00:00

Subject: Certificate validation error (500) using APIM Standard v2 send-request to backend with self-signed cert

Description:
Hello Azure Support,

I am attempting to send an HTTPS request from an API Management outbound policy to an Azure VM over its public IP address.

Current Configuration:

  • APIM Tier: Standard v2

Policy: Initially using <send-one-way-request>, but temporarily switched to <send-request> to capture the error trace.

Authentication: The backend VM is using a self-signed certificate. I attached the client certificate using the <authentication-certificate> fragment.

Network: The VM's Network Security Group (NSG) is configured to allow inbound TCP over port 443.

Backend Entity: I created a Custom Backend entity in APIM that uses the CA certificate, but I could not successfully attach or reference it within my policy XML.

Status: The APIM trace confirms the client certificate is attaching properly: "Certificate was attached to request per configuration."

The Issue: When using <send-one-way-request>, the request simply does not arrive at the destination. To troubleshoot, I switched to <send-request>, which revealed that the backend call fails with a 500 error. The request-forwarder trace outputs the following rejection, as APIM does not trust the self-signed server certificate:

JSON
{ "messages": [ "Error occured while calling backend service.", "The remote certificate was rejected by the provided RemoteCertificateValidationCallback." ] }

My Questions:

  1. How can I configure APIM to bypass or trust this specific self-signed backend certificate strictly by using policy fragments?
  2. Are there specific XML attributes or inline configurations I can add directly inside the <send-request> or <send-one-way-request> block to ignore this remote certificate validation error in the Standard v2 tier?

Thank you

Azure API Management
Azure API Management

An Azure service that provides a hybrid, multi-cloud management platform for APIs.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Christos Panagiotidis 3,566 Reputation points
    2026-07-15T07:38:48.94+00:00

    The trace is expected: authentication-certificate configures the client side of mTLS; it does not make APIM trust the certificate presented by the VM.

    There is no attribute in send-request or send-one-way-request that bypasses server-certificate validation. In Standard v2, configure the custom CA under the backend entity's Authorization credentials, use a DNS hostname that matches the certificate SAN, and route the API request through that backend with set-backend-service backend-id and the normal backend pipeline.

    A side call that uses set-url with the VM's public IP does not inherit those backend settings. If it must remain a side call, give the VM endpoint a publicly trusted certificate for a DNS name (or place a trusted HTTPS endpoint in front of it).

    Was this answer helpful?


  2. Gursimran Singh 570 Reputation points Microsoft External Staff Moderator
    2026-07-14T17:56:39.7766667+00:00

    Hello @Itzhaki, Shahar

    Thank you for the detailed information and trace results.

    Based on the trace, APIM is successfully attaching the client certificate to the outbound request. However, the request is failing during the TLS handshake because the certificate presented by the backend VM is not trusted by API Management, resulting in the following error:

    "The remote certificate was rejected by the provided RemoteCertificateValidationCallback"

    The trace message*"Certificate was attached to request per configuration"* confirms that the client certificate is being attached successfully. The <authentication-certificate> policy is used only for outbound client certificate authentication and does not affect validation of the backend server certificate. Microsoft documentation for backend client certificate authentication can be found here:

    Secure backend services using client certificate authentication [Secure API...entication], [Secure API...Management]

    For APIM Standard v2, trust for self-signed or custom CA certificates should be configured through the Backend entity. Microsoft documentation indicates that custom CA certificate details can be configured in the backend entity to establish trust for self-signed certificates, untrusted root certificates, or incomplete certificate chains:

    Backends in Azure API Management [Azure API...osoft Docs]

    To further validate the configuration, please review the following:

    Verify the certificate presented by the backend VM.

    Verify that the certificate is not expired and that the certificate chain is complete.

    Verify that the hostname being called matches the certificate CN/SAN.

    Navigate to APIM → Backends → Backend Entity → Authorization Credentials → CA Certificates and configure the appropriate CA certificate details for the backend certificate chain. Additional guidance is available here:

    Custom CA Certificates in API Management [Add a Cust...osoft Docs], [Azure API...osoft Docs]

    Retest the request after the backend trust configuration has been applied.

    Based on the Microsoft documentation reviewed, there is currently no documented policy attribute within <send-request> or <send-one-way-request> that can be used to bypass backend server certificate validation. Backend certificate trust must be established through backend configuration rather than policy XML. This behavior is documented in:

    Backends in Azure API Management

    Please accept as Yes if the answer is helpful so that it can help others in the community.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.