Hello @Itzhaki, Shahar
Thank you for the detailed information and trace results.
Based on the trace, APIM is successfully attaching the client certificate to the outbound request. However, the request is failing during the TLS handshake because the certificate presented by the backend VM is not trusted by API Management, resulting in the following error:
"The remote certificate was rejected by the provided RemoteCertificateValidationCallback"
The trace message*"Certificate was attached to request per configuration"* confirms that the client certificate is being attached successfully. The <authentication-certificate> policy is used only for outbound client certificate authentication and does not affect validation of the backend server certificate. Microsoft documentation for backend client certificate authentication can be found here:
Secure backend services using client certificate authentication [Secure API...entication], [Secure API...Management]
For APIM Standard v2, trust for self-signed or custom CA certificates should be configured through the Backend entity. Microsoft documentation indicates that custom CA certificate details can be configured in the backend entity to establish trust for self-signed certificates, untrusted root certificates, or incomplete certificate chains:
Backends in Azure API Management [Azure API...osoft Docs]
To further validate the configuration, please review the following:
Verify the certificate presented by the backend VM.
Verify that the certificate is not expired and that the certificate chain is complete.
Verify that the hostname being called matches the certificate CN/SAN.
Navigate to APIM → Backends → Backend Entity → Authorization Credentials → CA Certificates and configure the appropriate CA certificate details for the backend certificate chain. Additional guidance is available here:
Custom CA Certificates in API Management [Add a Cust...osoft Docs], [Azure API...osoft Docs]
Retest the request after the backend trust configuration has been applied.
Based on the Microsoft documentation reviewed, there is currently no documented policy attribute within <send-request> or <send-one-way-request> that can be used to bypass backend server certificate validation. Backend certificate trust must be established through backend configuration rather than policy XML. This behavior is documented in:
Backends in Azure API Management
Please accept as Yes if the answer is helpful so that it can help others in the community.