How to use a Cloudflare origin certificate on an Azure App

  • I am assuming that you followed my guide to Setup a Cloudflare Origin Certificate.

    1. Log on to a Linux based system of any type.
      • If you like annoying, and you might since you are using Azure, feel free to get openssl setup on Windows. Just don't ask me.
    2. Save the origin certificate file as origin.domain.pem.
    3. Save the origin key file as origin.domain.key.
    4. Save the chain file (ECC version) as chain.domain.pem.
      You should end up with this.
    [[email protected] Azure]$ ls -las
    total 24
    4 drwxrwxr-x. 2 jbusch jbusch 4096 Apr 28 23:14 .
    4 drwxrwxr-x. 3 jbusch jbusch 4096 Apr 28 23:10 ..
    4 -rw-rw-r--. 1 jbusch jbusch  939 Apr 28 23:10
    4 -rw-rw-r--. 1 jbusch jbusch  241 Apr 28 23:11
    4 -rw-rw-r--. 1 jbusch jbusch 1151 Apr 28 23:11
    1. Create the PFX certificate with with a passcode using openssl
    [[email protected] Azure]$ openssl pkcs12 -export -in -inkey -out -certfile
    Enter Export Password: samepasswordtwice
    Verifying - Enter Export Password: samepasswordtwice
    [[email protected] Azure]$ 
    1. Add a cname in Cloudflare for your domain pointing to your Make sure the orange cloud is unchecked for now.

    2. Sign in to Azure, go to the App services, click on your app, and then Custom domains.

    3. Click Add custom domain and put in the domain in the box and click validate.

    4. Wait a moment while it checks for hte DNS record, and then click the Add custom domain box above the two green checks ✅.

    5. Click Add binding on the prior panel.

    6. Click the Upload PFX Certificate button.

    7. Browse to the file and enter the password, then click upload.
      Save it off the Linux machine if you need to back to your desktop.

    8. It will upload and thn you have to choose the certificate and type. Each box only has one option.

    9. Choose the only options and click Add Binding at the bottom.

    10. You will see the new domain showing and have the secure check mark.

    11. Go back over to Cloudflare and turn on the orange cloud.

    12. Optionally, this depends on the other DNS entries you have with the orange cloud all having valid SSL, you can enable Strict SSL.