Blog Post

Internet of Things Blog

Known issue: Azure Sphere tenant CA certificate rotation

skothari's avatar
Icon for Microsoft rankMicrosoft
Jul 30, 2020

What is the issue?

We discovered an issue that affects verification of tenant certificates and we are resolving this by renewing the tenant CA certificates for all impacted tenants. As described in the blog Azure Sphere tenant CA certificate management: certificate rotation, the Azure Sphere tenant certificate authority (CA) certificates that were issued two years ago are being automatically renewed. The Azure Sphere 20.07 SDK, released on July 29, 2020, supports features with which you can download the renewed certificates for your tenants. For certificates created between June 16, 2020 21:00 UTC, and July 28, 2020 00:15 UTC, verification using OpenSSL may fail. The failure is due to a mismatched signature algorithm identifier in the certificate. The error does not compromise the security of these certificates.


Who is impacted?

If the tenant CA certificate issuance date is after June 16, 2020 and before July 28, 2020, the tenant CA certificate may fail to verify with OpenSSL. The Azure Sphere Security Service will renew and activate all impacted certificates as a corrective measure.


What actions should you take?



You have not downloaded the tenant CA certificate or tenant CA certificate chain that was issued between June 16, 2020 and July 28, 2020


(If you run ‘azsphere ca list’ in your Azure Sphere Development command prompt, you will see this issue date listed as “Start date”)

You don’t have any actions to take and these instructions don’t apply to you.

You have downloaded the tenant CA certificate or tenant CA certificate chain that was issued between June 16, 2020 and July 28, 2020

Between August 5, 2020 and August 18, 2020, please follow the instructions below to ensure that there is no break in service.

  • Run ‘azsphere ca list’ in your Azure Sphere Development command prompt
  • Use the most recent certificate to register with Azure IoT Hub/Central or other third-party resources following instructions here



For tenants that are impacted by this issue, the new and valid tenant CA certificates will be created by August 5, 2020. The new certificates will be activated after August 18, 2020. If you have any additional questions, please reach out to Microsoft Support.


Documentation Resources:

Updated Jul 30, 2020
Version 1.0