Azure-docs: Key Thumbprint discrepancy between portal and New-AzureADApplicationKeyCredential

Created on 27 Jul 2018  Â·  6Comments  Â·  Source: MicrosoftDocs/azure-docs

Hi,
I have noticed that according to the way keys were associated to applications, their thumbprint shown in the App Registrations > The Application > Settings > keys page end up different...
It's only when the public key is uploaded through the portal that its thumbprint is the same as when accessing the certificate in the Microsoft Management Console.
Using New-AzureADApplicationKeyCredential displays a much longer thumbprint.
Any insight about how it's calculated would be appreciated as it would ease spotting them in case we want to revoke one.
Right now I fall back on computing its CustomKeyIdentifier and removing it manually from the Application Manifest.
Thanks and kind regards.
Is there a good reason for it ?


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Pri2 active-directorsvc cxp in-progress product-issue triaged

Most helpful comment

Hi @SaurabhSharma-MSFT
this is still an issue. when using the New-AzureADApplicationKeyCredential as described in
https://docs.microsoft.com/en-us/powershell/module/azuread/new-azureadapplicationkeycredential?view=azureadps-2.0#example-2--use-a-certificate-to-add-an-application-key-credential

=> the thumbprint in the portal shows as "Thumbprint not available". the credentials does work.

All 6 comments

Thanks for the feedback! We are looking into this and will get back to you shortly.

Its a known issue and is the process of being fixed.

Certificates created through PowerShell are created using a different encoding than the certificates created through the Ibiza Portal, and a bug in UI does not handle these two different encoding correctly.

@kalyankrishna1 Thanks Kalyan for the update.
@chaami We will now proceed to close this thread. If there are further questions regarding this matter, please reopen it and we will gladly continue the discussion.

Hi, @SaurabhSharma-MSFT , @kalyankrishna1 .
Thanks a lot for the precious information.
Can we keep this issue open until the problem is fixed or link to another issue tracking the progress ?
Also, it seems that I can't reopen this but only comment 😉
Kind regards,
Amine

Hello, I know this is sort of an old post, but is it still a known issue when using the New-AzureADApplicationKeyCredential command that the customKeyIdentifier is incorrect in the portal but looks right when creating it in PowerShell?

Hi @SaurabhSharma-MSFT
this is still an issue. when using the New-AzureADApplicationKeyCredential as described in
https://docs.microsoft.com/en-us/powershell/module/azuread/new-azureadapplicationkeycredential?view=azureadps-2.0#example-2--use-a-certificate-to-add-an-application-key-credential

=> the thumbprint in the portal shows as "Thumbprint not available". the credentials does work.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

jebeld17 picture jebeld17  Â·  3Comments

spottedmahn picture spottedmahn  Â·  3Comments

monteledwards picture monteledwards  Â·  3Comments

behnam89 picture behnam89  Â·  3Comments

jharbieh picture jharbieh  Â·  3Comments