An extension of Azure for running apps in an on-premises environment and delivering Azure services in a datacenter.
External certificate rotation on Azure Stack Hub must follow the Azure Stack Hub PKI certificate requirements and must pass the Readiness Checker/validation step before being used for deployment or rotation.
The provided context explicitly states that before rotating external secrets you must:
- Generate CSRs using the documented process.
- Prepare the returned certificates using the Prepare PKI certificates guidance.
- Validate them using Validate PKI Certificates.
If the validation tool reports an error or non‑compliance (for example, because the EKU does not match what Azure Stack Hub expects), those certificates are not considered supported for rotation. The documentation does not provide an exception or override mechanism for EKU or other certificate requirement violations, and it does not state that certificates failing validation will still work.
Because of this, only certificates that meet the documented PKI requirements and pass the validation step are supported for Azure Stack Hub external secret rotation. Certificates that differ from the required EKU profile and cause validation failures are not supported for use.
If requesting a different certificate from the CA is not possible, the supported path is to work with the CA to obtain certificates that meet the Azure Stack Hub PKI certificate requirements, or to open a support case with Microsoft to review the specific validation output and options.
References: