Used by Azure Firewall Premium to sign server certificates on the fly during TLS inspection, this CA certificate must be exportable and is kept as a Key Vault secret. A user-assigned managed identity gives the firewall access, and clients need to trust the root above it.
Also called Azure Firewall Premium.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Intermediate CA certificate in context, with comparison tables and the common traps.
Terms in this definition
- Azure Firewall Premium
Top Azure Firewall SKU, which builds on Standard with IDPS, TLS inspection, URL filtering and web categories; using those features requires a firewall policy on the Premium tier.
- TLS inspection
With an intermediate CA certificate held in Key Vault, Azure Firewall Premium can decrypt outbound and east-west TLS traffic, inspect it and encrypt it again.
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- Key Vault secret
String value kept in Key Vault, for example a password, connection string or API key.
- UAMI
A user-assigned managed identity: an Azure resource of its own that can be attached to services. Mirroring Azure SQL Database requires the logical server to have a primary identity enabled, which may be its system-assigned identity or, in preview, a UAMI.
Related terms
- Trusted certificate profile
Delivers a root or intermediate CA certificate via Intune, so certificates from that CA are accepted. Target it at whichever groups also get dependent SCEP or PKCS profiles.