Azure-docs: Instructions are a bit ambiguous

Created on 16 Dec 2019  Â·  5Comments  Â·  Source: MicrosoftDocs/azure-docs

I'm trying to follow the instructions on this page via the Portal but am not having much luck. On the "Add multi-site listener" blade I select the Key Vault but it shows a "The key vault must have GET permissions on the secret" error; I have created a policy to grant Get certificate permissions for the user-assigned Managed Identity. Am I doing something wrong? Does the App Gateway need a role assignment on the Key Vault as well?

Does the lack of explicit portal instructions mean that you can only (currently) do this using PowerShell (https://docs.microsoft.com/en-us/azure/application-gateway/configure-keyvault-ps)?


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Pri2 application-gatewasvc assigned-to-author doc-enhancement triaged

All 5 comments

@philipstreet-hiscox Thanks for the feedback! I would use PowerShell, as we have clearly outlined instructions for configuring this via PowerShell.

To add instructions for the portal, I have assigned this issue to the content author to evaluate and update as appropriate.

@philipstreet-hiscox the user assigned identity only requires get permissions on the secrets. no additional role assignments are required. In the PowerShell example you can see this line:
Set-AzKeyVaultAccessPolicy -VaultName $kv -PermissionsToSecrets get -ObjectId $identity.PrincipalId

It says in "2. Configure your key vault" that it's recommended to store certificates as Certificates in the KV, not as Secrets. And in so doing, it would be '-permissionstocertificates get' that is required.

Encountering this as well, seems a little misleading as I'm given a list of certificates, not secrets. Also, I have already granted GET permission to the user managed identity that is being used.

Something doesn't seem right here.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Agazoth picture Agazoth  Â·  3Comments

monteledwards picture monteledwards  Â·  3Comments

behnam89 picture behnam89  Â·  3Comments

jharbieh picture jharbieh  Â·  3Comments

bdcoder2 picture bdcoder2  Â·  3Comments