APIM Custom Domain certificate not refreshing automatically

Anonymous
2023-12-20T13:01:45.2+00:00

We are using API Management with a Custom Domain assigned to the Gateway endpoint. This Custom Domain uses a certificate. The certificate is stored in Key Vault and we are referencing it from the APIM Custom Domains section.

We have been using the infrastructure for a year already and now the time to refresh the certificate occurred. We've updated the certificate in the Key Vault and waited for some time, but for around 30 minutes, we have not seen any change. We are using the same certificate in the Certificates section of another APIM, and this was reloaded manually (Fetch key vault secret button) and started to work immediately.

In the case of Custom Domains, we had to make a random change there, and save it, which triggered the updating process, and after around 50 minutes, it propagated correctly. However, this is a very inconvenient way. Even though the API had no real downtime as stated in the docs, the clients (who refreshed the certificates immediately) were not able to call our APIM (getting certificate mismatch).

Is there some instant way to refresh the certificate immediately? Or at least in some reasonable and predictable time slot?

Azure API Management
Azure API Management

An Azure service that provides a hybrid, multi-cloud management platform for APIs.

0 comments No comments

3 answers

Sort by: Most helpful
  1. MuthuKumaranMurugaachari-MSFT 22,451 Reputation points Moderator
    2023-12-20T15:04:43.45+00:00

    Michal Pipal Thanks for posting your question in Microsoft Q&A. I assume you followed doc: Configure a custom domain name for your Azure API Management instance in setting custom domain for APIM gateway in reference to Azure Key Vault. Make sure you had set them to autorenew and inserted as a certificate (not secret) as described in the doc.

    If you had already set them, APIM will pick up the changes from Azure Key Vault in a few hours (except Developer tier) and apply it automatically. In case, the client calling APIM has certificate pinning by thumbprint, then it should be updated beforehand.

    Note: The current poll time to refresh changes from Key Vault is 4 hours (may change in future) and applying the certificate might take up to 20 mins. Refer Certificate options for this info:

    User's image

    For immediately refresh the certificate, you can update it manually via portal or PUT command using rest API.

    I hope this helps with your questions and let me know if you have any other.


    If you found the answer to your question helpful, please take a moment to mark it as Yes for others to benefit from your experience. Or simply add a comment tagging me and would be happy to answer your questions.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. Italo Paolo Orellana León 0 Reputation points
    2026-09-27T16:46:33.07+00:00

    Title: APIM Standard v2 behind Application Gateway: custom domain stopped working after Key Vault certificate rotation (502 Bad Gateway)

    Environment

    • Azure API Management Standard v2, accessed privately through a private endpoint
    • Azure Application Gateway v2 (WAF) in front of APIM, with the backend pool pointing to the APIM private endpoint IP
    • Custom gateway domain api.contoso.com configured in APIM with a Key Vault certificate (unversioned secret identifier, auto-rotation)
    • Public DNS: api.contoso.com → A record pointing to the Application Gateway public IP
    • During the initial deployment, api.contoso.com was temporarily a CNAME to contoso-apim.azure-api.net, so the custom domain could be assigned. It was later changed to the A record so that all traffic goes through the WAF.

    Symptom After a new certificate version was imported into Key Vault as part of a regular renewal, the Application Gateway started returning 502 Bad Gateway. Backend health showed:

    The Common Name (CN) of the backend server certificate does not match the host header entered in the health probe configuration.

    A TLS test against the private endpoint IP showed:

    • SNI api.contoso.com → the gateway presented CN=*.azurewebsites.net (platform default certificate)
    • SNI contoso-apim.azure-api.net → the gateway presented CN=*.azure-api.net and /status-0123456789abcdef returned 200

    So the gateway had lost the custom domain binding, while the portal still showed the old certificate thumbprint in Custom domains.

    What did not work

    • Sync certificates: no effect. View sync logs showed no entries.
    • Waiting for the automatic rotation. The Activity log showed AUTO UPDATE SSL CERTIFICATE STARTED, and its payload already contained the new thumbprint, so Key Vault access and managed identity permissions were fine.
    • Disabling the old certificate version in Key Vault.
    • Updating the custom domain with a manually uploaded PFX: the operation Create or Update API Management Service instance failed with a generic "Unable to Update API service at this time" error and the configuration rolled back.

    Root cause During certificate rotation, Standard v2 appears to re-validate the custom domain against public DNS. That validation expects api.contoso.com to resolve (CNAME) to contoso-apim.azure-api.net. Because the public record points to the Application Gateway, the validation failed and the custom domain binding was dropped. The initial deployment worked only because the CNAME existed at the time the domain was assigned.

    This behavior is not explicitly described in the official rotation documentation, which states that Key Vault certificates are picked up automatically without downtime in SLA tiers. It is, however, consistent with the Standard v2 limitation on publicly resolvable custom domain names, and with the recent Tech Community article "Your Certificate Renewed. Your Gateway Didn't Notice."

    Resolution

    1. Temporarily changed the public DNS record api.contoso.com from the A record to a CNAME → contoso-apim.azure-api.net (low TTL).
    2. After propagation, APIM validated the domain and applied the new certificate. Custom domains showed the new thumbprint, and the TLS test on SNI api.contoso.com returned the correct certificate.
    3. Restored the public A record → Application Gateway public IP.
    4. Application Gateway backend health returned to Healthy (200) and the service was restored.

    Lessons learned / recommendations

    • With APIM v2 behind Application Gateway, Front Door or Traffic Manager, every certificate renewal may require the temporary CNAME step, unless the design changes.
    • More robust alternatives:
      • Configure the Application Gateway backend settings and probe to use the APIM default hostname (contoso-apim.azure-api.net) and manage the public certificate only on the Application Gateway listener. This is the workaround suggested in the v2 documentation.
        • Or use a different custom domain in APIM (for example apim-internal.contoso.com) with a permanent public CNAME to *.azure-api.net.
        • Keep a low TTL on the public record so the temporary change propagates quickly.
        • Monitor the Activity log for AUTO UPDATE SSL CERTIFICATE events and alert on failures.

    Question for the community / Microsoft: Is there a supported way to validate domain ownership for a Standard v2 custom domain (for example, a TXT record) when the public DNS name must point to an Application Gateway or WAF, so that certificate rotation does not depend on changing the public DNS?Title: APIM Standard v2 behind Application Gateway: custom domain stopped working after Key Vault certificate rotation (502 Bad Gateway)

    Environment

    • Azure API Management Standard v2, accessed privately through a private endpoint
    • Azure Application Gateway v2 (WAF) in front of APIM, with the backend pool pointing to the APIM private endpoint IP
    • Custom gateway domain api.contoso.com configured in APIM with a Key Vault certificate (unversioned secret identifier, auto-rotation)
    • Public DNS: api.contoso.com → A record pointing to the Application Gateway public IP
    • During the initial deployment, api.contoso.com was temporarily a CNAME to contoso-apim.azure-api.net, so the custom domain could be assigned. It was later changed to the A record so that all traffic goes through the WAF.

    Symptom
    After a new certificate version was imported into Key Vault as part of a regular renewal, the Application Gateway started returning 502 Bad Gateway. Backend health showed:

    The Common Name (CN) of the backend server certificate does not match the host header entered in the health probe configuration.

    A TLS test against the private endpoint IP showed:

    • SNI api.contoso.com → the gateway presented CN=*.azurewebsites.net (platform default certificate)
    • SNI contoso-apim.azure-api.net → the gateway presented CN=*.azure-api.net and /status-0123456789abcdef returned 200

    So the gateway had lost the custom domain binding, while the portal still showed the old certificate thumbprint in Custom domains.

    What did not work

    • Sync certificates: no effect. View sync logs showed no entries.
    • Waiting for the automatic rotation. The Activity log showed AUTO UPDATE SSL CERTIFICATE STARTED, and its payload already contained the new thumbprint, so Key Vault access and managed identity permissions were fine.
    • Disabling the old certificate version in Key Vault.
    • Updating the custom domain with a manually uploaded PFX: the operation Create or Update API Management Service instance failed with a generic "Unable to Update API service at this time" error and the configuration rolled back.

    Root cause
    During certificate rotation, Standard v2 appears to re-validate the custom domain against public DNS. That validation expects api.contoso.com to resolve (CNAME) to contoso-apim.azure-api.net. Because the public record points to the Application Gateway, the validation failed and the custom domain binding was dropped. The initial deployment worked only because the CNAME existed at the time the domain was assigned.

    This behavior is not explicitly described in the official rotation documentation, which states that Key Vault certificates are picked up automatically without downtime in SLA tiers. It is, however, consistent with the Standard v2 limitation on publicly resolvable custom domain names, and with the recent Tech Community article "Your Certificate Renewed. Your Gateway Didn't Notice."

    Resolution

    1. Temporarily changed the public DNS record api.contoso.com from the A record to a CNAME → contoso-apim.azure-api.net (low TTL).
    2. After propagation, APIM validated the domain and applied the new certificate. Custom domains showed the new thumbprint, and the TLS test on SNI api.contoso.com returned the correct certificate.
    3. Restored the public A record → Application Gateway public IP.
    4. Application Gateway backend health returned to Healthy (200) and the service was restored.

    Lessons learned / recommendations

    • With APIM v2 behind Application Gateway, Front Door or Traffic Manager, every certificate renewal may require the temporary CNAME step, unless the design changes.
    • More robust alternatives:
      • Configure the Application Gateway backend settings and probe to use the APIM default hostname (contoso-apim.azure-api.net) and manage the public certificate only on the Application Gateway listener. This is the workaround suggested in the v2 documentation.
        • Or use a different custom domain in APIM (for example apim-internal.contoso.com) with a permanent public CNAME to *.azure-api.net.
        • Keep a low TTL on the public record so the temporary change propagates quickly.
        • Monitor the Activity log for AUTO UPDATE SSL CERTIFICATE events and alert on failures.

    Question for the community / Microsoft: Is there a supported way to validate domain ownership for a Standard v2 custom domain (for example, a TXT record) when the public DNS name must point to an Application Gateway or WAF, so that certificate rotation does not depend on changing the public DNS?

    Was this answer helpful?


  3. Venkatraman Natarajan 0 Reputation points
    2025-05-20T17:06:46.3533333+00:00

    Hi Everyone,

    In Consumption plan APIM, the certificate is not refreshed even after 12 hours. We need to upload latest cert every year in keyvault then APIM should fetch automatically. It is happening in Premium tier APIM but not in consumption plan.

    Could you please help us on this?

    Thanks,

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.