question

IldikoDencsak-5601 avatar image
0 Votes"
IldikoDencsak-5601 asked MarileeTurscak-MSFT commented

No notification received about certificate expiration

About a year ago we created an App Service Certificate in the Azure portal and imported in into a key vault. Auto-renew was not configured.
The certificate expired in the meantime, but we did not receive any notification before the expiry time.

While investigating, I found that in order to get notified, we should have set a certificate contact:

https://docs.microsoft.com/en-us/azure/key-vault/certificates/overview-renew-certificate
"To get notified about certificate life events, you would need to add certificate contact. Certificate contacts contain contact information to send notifications triggered by certificate lifetime events. The contacts information is shared by all the certificates in the key vault. A notification is sent to all the specified contacts for an event for any certificate in the key vault."

This doc states that it should be possible to set a certificate contact both from the Azure portal and PowerShell:

https://docs.microsoft.com/en-us/azure/key-vault/certificates/overview-renew-certificate#steps-to-set-certificate-notifications
"First, add a certificate contact to your key vault. You can add using Azure portal or PowerShell cmdlet Add-AzureKeyVaultCertificateContact."

The issue is that I cannot find the place to configure this in the Azure portal.
Can you please guide me in the right direction?


azure-key-vault
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

MarileeTurscak-MSFT avatar image
0 Votes"
MarileeTurscak-MSFT answered MarileeTurscak-MSFT commented

Hi @IldikoDencsak-5601,

In the Azure Portal you can do this by going to the Key Vault > Certificates (under Settings) > Certificate Contacts (in the top right corner):

92261-image.png

92254-image.png

Hope this helps!



If this answer was helpful to you, please remember to "mark as answer" so that others in the community can more easily find a solution.




image.png (51.6 KiB)
image.png (70.4 KiB)
· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

You're right, it seems so obvious now that you pointed it out!
I've been working with secrets and kept searching for this setting in the Overview and Properties tab.

Thank you for the quick answer!

0 Votes 0 ·

how soon the notifications sent out? a month before certificate expiry or a week before.?

0 Votes 0 ·
MarileeTurscak-MSFT avatar image MarileeTurscak-MSFT KarthikeyanSaravananS-1488 ·

Based on my testing it happens three days before the renewal date.

1 Vote 1 ·