Additional certificate updates for Azure Sphere

Published Sep 29 2020 04:30 PM 1,678 Views
Regular Visitor

by Penny Orwick, Principal Program Manager, Azure Sphere

 

Additional certificate updates for Azure Sphere

Microsoft is updating Azure services, including Azure Sphere, to use intermediate TLS certificates from a different set of Certificate Authorities (CAs). These updates are being phased in gradually, starting in August 2020 and completing by October 26, 2020. This change is being made because existing intermediate certificates do not comply with one of the CA/Browser Forum Baseline requirements. See Azure TLS Certificate Changes for a description of upcoming certificate changes across Azure products. Azure IoT TLS: Changes are coming! (…and why you should care) provides details about the reasons for the certificate changes and how they affect the use of Azure IoT.

 

How does this affect Azure Sphere?

On October 13, 2020 we will update the Azure Sphere Security Service SSL certificates. Please read on to determine whether this update will require any action on your part.

 

What customer actions are required for the SSL certificate updates?

On October 13, 2020 the SSL certificate for the Azure Sphere Public API will be updated to a new leaf certificate that links to the new DigiCert Global Root G2 certificate. This change will affect only the use of the Public API. It does not affect Azure Sphere applications that run on the device.

 

For most customers, no action is necessary in response to this change because Windows and Linux systems include the DigiCert Global Root G2 certificate in their system certificate stores. The new SSL certificate will automatically migrate to use the DigiCert Global Root G2 certificate.

 

However, if you “pin” any intermediate certificates or require a specific subject, name, or issuer (“SNI pinning”), you will need to update your validation process. To avoid losing connectivity to the Azure Sphere Public API, you must make this change before we update the certificate on October 13, 2020.

 

What about Azure Sphere apps that use IoT and other Azure services?

Additional certificate changes will occur soon that affect Azure IoT and other Azure services. The update to the SSL certificates for the Azure Sphere Public API is separate from those changes.

 

Azure IoT TLS: Changes are coming! (…and why you should care) describes the upcoming changes that will affect IoT Hub, IoT Central, DPS, and Azure Storage Services. These services are not changing their Trusted Root CAs; they are only changing their intermediate certificates. Azure Sphere on-device applications that use only the Azure IoT and Azure Sphere application libraries should not require any modifications. When future certificate changes are required, we will update the IoT C SDK in the Azure Sphere OS and thus make the updated certificates available to your apps.

 

If your Azure Sphere on-device applications communicate with other Azure services, however, and pin or supply certificates for those services, you might need to update your image package to include updated certificates. See Azure TLS Certificate Changes for information about which certificates are changing and what changes you need to make.  

 

We continue to test common Azure Sphere scenarios as other teams at Microsoft perform certificate updates and will provide detailed information if additional customer action is required.

 

For more information:

If you encounter problems

For self-help technical inquiries, please visit Microsoft Q&A or Stack Overflow. If you require technical support and have a support plan, please submit a support ticket in Microsoft Azure Support or work with your Microsoft Technical Account Manager/Technical Specialist. If you would like to purchase a support plan, please explore the Azure support plans.

 

%3CLINGO-SUB%20id%3D%22lingo-sub-1727037%22%20slang%3D%22en-US%22%3EAdditional%20certificate%20updates%20for%20Azure%20Sphere%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1727037%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EAdditional%20certificate%20updates%20for%20Azure%20Sphere%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EMicrosoft%20is%20updating%20Azure%20services%2C%20including%20Azure%20Sphere%2C%20to%20use%20intermediate%20TLS%20certificates%20from%20a%20different%20set%20of%20Certificate%20Authorities%20(CAs).%20These%20updates%20are%20being%20phased%20in%20gradually%2C%20starting%20in%20August%202020%20and%20completing%20by%20October%2026%2C%202020.%20This%20change%20is%20being%20made%20because%20existing%20intermediate%20certificates%20do%20not%20comply%20with%20one%20of%20the%20CA%2FBrowser%20Forum%20Baseline%20requirements.%20See%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fkey-vault%2Fgeneral%2Fwhats-new%23azure-tls-certificate-changes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20TLS%20Certificate%20Changes%3C%2FA%3E%3CSPAN%3E%20for%20a%20description%20of%20upcoming%20certificate%20changes%20across%20Azure%20products.%20%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Finternet-of-things%2Fazure-iot-tls-changes-are-coming-and-why-you-should-care%2Fba-p%2F1658456%22%20target%3D%22_blank%22%3EAzure%20IoT%20TLS%3A%20Changes%20are%20coming!%20(%E2%80%A6and%20why%20you%20should%20care)%3C%2FA%3E%26nbsp%3Bprovides%20details%20about%20the%20reasons%20for%20the%20certificate%20changes%20and%20how%20they%20affect%20the%20use%20of%20Azure%20IoT.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EHow%20does%20this%20affect%20Azure%20Sphere%3F%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EOn%20October%2013%2C%202020%20we%20will%20update%20the%20Azure%20Sphere%20Security%20Service%20SSL%20certificates.%20Please%20read%20on%20to%20determine%20whether%20this%20update%20will%20require%20any%20action%20on%20your%20part.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EWhat%20customer%20actions%20are%20required%20for%20the%20SSL%20certificate%20updates%3F%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EOn%20October%2013%2C%202020%20the%20SSL%20certificate%20for%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Frest%2Fapi%2Fazure-sphere%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Sphere%20Public%20API%3C%2FA%3E%20will%20be%20updated%20to%20a%20new%20leaf%20certificate%20that%20links%20to%20the%20new%20DigiCert%20Global%20Root%20G2%20certificate.%20This%20change%20will%20affect%20only%20the%20use%20of%20the%20Public%20API.%20It%20does%20not%20affect%20Azure%20Sphere%20applications%20that%20run%20on%20the%20device.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20most%20customers%2C%20no%20action%20is%20necessary%20in%20response%20to%20this%20change%20because%20Windows%20and%20Linux%20systems%20include%20the%20DigiCert%20Global%20Root%20G2%20certificate%20in%20their%20system%20certificate%20stores.%20The%20new%20SSL%20certificate%20will%20automatically%20migrate%20to%20use%20the%20DigiCert%20Global%20Root%20G2%20certificate.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHowever%2C%20if%20you%20%E2%80%9Cpin%E2%80%9D%20any%20intermediate%20certificates%20or%20require%20a%20specific%20subject%2C%20name%2C%20or%20issuer%20(%E2%80%9CSNI%20pinning%E2%80%9D)%2C%20you%20will%20need%20to%20update%20your%20validation%20process.%20To%20avoid%20losing%20connectivity%20to%20the%20Azure%20Sphere%20Public%20API%2C%20you%20must%20make%20this%20change%20before%20we%20update%20the%20certificate%20on%20October%2013%2C%202020.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EWhat%20about%20Azure%20Sphere%20apps%20that%20use%20IoT%20and%20other%20Azure%20services%3F%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EAdditional%20certificate%20changes%20will%20occur%20soon%20that%20affect%20Azure%20IoT%20and%20other%20Azure%20services.%20The%20update%20to%20the%20SSL%20certificates%20for%20the%20Azure%20Sphere%20Public%20API%20is%20separate%20from%20those%20changes.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Finternet-of-things%2Fazure-iot-tls-changes-are-coming-and-why-you-should-care%2Fba-p%2F1658456%22%20target%3D%22_blank%22%3EAzure%20IoT%20TLS%3A%20Changes%20are%20coming!%20(%E2%80%A6and%20why%20you%20should%20care)%3C%2FA%3E%20describes%20the%20upcoming%20changes%20that%20will%20affect%20IoT%20Hub%2C%20IoT%20Central%2C%20DPS%2C%20and%20Azure%20Storage%20Services.%20These%20services%20are%20not%20changing%20their%20Trusted%20Root%20CAs%3B%20they%20are%20only%20changing%20their%20intermediate%20certificates.%20Azure%20Sphere%20on-device%20applications%20that%20use%20only%20the%20Azure%20IoT%20and%20Azure%20Sphere%20application%20libraries%20should%20not%20require%20any%20modifications.%20When%20future%20certificate%20changes%20are%20required%2C%20we%20will%20update%20the%20IoT%20C%20SDK%20in%20the%20Azure%20Sphere%20OS%20and%20thus%20make%20the%20updated%20certificates%20available%20to%20your%20apps.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20your%20Azure%20Sphere%20on-device%20applications%20communicate%20with%20other%20Azure%20services%2C%20however%2C%20and%20pin%20or%20supply%20certificates%20for%20those%20services%2C%20you%20might%20need%20to%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure-sphere%2Fapp-development%2Fcurl%23add-ca-certificates-to-the-image-package%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Eupdate%20your%20image%20package%3C%2FA%3E%20to%20include%20updated%20certificates.%20See%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fkey-vault%2Fgeneral%2Fwhats-new%23azure-tls-certificate-changes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20TLS%20Certificate%20Changes%3C%2FA%3E%20for%20information%20about%20which%20certificates%20are%20changing%20and%20what%20changes%20you%20need%20to%20make.%20%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20continue%20to%20test%20common%20Azure%20Sphere%20scenarios%20as%20other%20teams%20at%20Microsoft%20perform%20certificate%20updates%20and%20will%20provide%20detailed%20information%20if%20additional%20customer%20action%20is%20required.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EFor%20more%20information%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fkey-vault%2Fgeneral%2Fwhats-new%23azure-tls-certificate-changes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20TLS%20Certificate%20Changes%3C%2FA%3E%20provides%20detail%20about%20certificate%20changes%20for%20Azure%20services.%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Finternet-of-things%2Fazure-iot-tls-changes-are-coming-and-why-you-should-care%2Fba-p%2F1658456%22%20target%3D%22_blank%22%3EAzure%20IoT%20TLS%3A%20Changes%20are%20coming!%20(%E2%80%A6and%20why%20you%20should%20care)%3C%2FA%3E%20describes%20upcoming%20changes%20to%20the%20IoT%20Hub%2C%20IoT%20Central%2C%20DPS%2C%20and%20Azure%20Storage%20Services.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSTRONG%3EIf%20you%20encounter%20problems%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EFor%20self-help%20technical%20inquiries%2C%20please%20visit%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fanswers%2Fsearch.html%3Fc%3D%26amp%3BincludeChildren%3D%26amp%3Bf%3D%26amp%3Btype%3Dquestion%2BOR%2Bidea%2BOR%2Bkbentry%2BOR%2Banswer%2BOR%2Btopic%2BOR%2Buser%26amp%3Bredirect%3Dsearch%252Fsearch%26amp%3Bsort%3Drelevance%26amp%3Bq%3Dazure%2520sphere%2520OS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Q%26amp%3BA%3C%2FA%3E%26nbsp%3Bor%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fstackoverflow.com%252Fsearch%253Fq%253Dazuresphere%2526s%253D23550afd-6ece-47d5-a84f-2d0dc6fc9cf5%26amp%3Bdata%3D02%257C01%257Cdinaben%2540microsoft.com%257C0a7a21610b994f71650a08d819fd8d52%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637287924175577406%26amp%3Bsdata%3D5G724w3PM%252BdKmimLQfZzEY1TJ6q2kRRzuku3kgLO51w%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EStack%20Overflow%3C%2FA%3E.%20If%20you%20require%20technical%20support%20and%20have%20a%20support%20plan%2C%20please%20submit%20a%20support%20ticket%20in%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fms.portal.azure.com%2F%3Fquickstart%3Dtrue%26amp%3BCAF%3Dtrue%23blade%2FMicrosoft_Azure_Support%2FHelpAndSupportBlade%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMicrosoft%20Azure%20Support%3C%2FA%3E%26nbsp%3Bor%20work%20with%20your%20Microsoft%20Technical%20Account%20Manager%2FTechnical%20Specialist.%20If%20you%20would%20like%20to%20purchase%20a%20support%20plan%2C%20please%20explore%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fazuresupport%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20support%20plans%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1727037%22%20slang%3D%22en-US%22%3E%3CP%3EOn%20October%2013%2C%202020%20we%20will%20update%20the%20Azure%20Sphere%20Security%20Service%20SSL%20certificates.%20Please%20read%20on%20to%20determine%20whether%20this%20update%20will%20require%20any%20action%20on%20your%20part.%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22CLO17_electronicsFactory_016.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F222943i2D7971A015519B30%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22CLO17_electronicsFactory_016.jpg%22%20alt%3D%22CLO17_electronicsFactory_016.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1727037%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Sphere%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Sphere%20updates%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIoT%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIoT%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Version history
Last update:
‎Jan 04 2021 09:08 AM
Updated by: