Skip to content

Commit 060a60a

Browse files
authored
Update front-door-faq.yml
DigiCert CNAME DCV Deprecation
1 parent 47acfb3 commit 060a60a

File tree

1 file changed

+44
-0
lines changed

1 file changed

+44
-0
lines changed

articles/frontdoor/front-door-faq.yml

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -268,7 +268,51 @@ sections:
268268
Front Door uses TLS 1.2 as the minimum version for all profiles created after September 2019.
269269
270270
You can choose to use TLS 1.2 or 1.3 with Azure Front Door. To learn more, read the [Azure Front Door end-to-end TLS](concept-end-to-end-tls.md) article.
271+
272+
- name: Certificate Management and DigiCert DCV Workflow Deprecation
273+
questions:
271274

275+
- question: |
276+
What is happening with DigiCert’s CNAME Delegation DCV workflow?
277+
answer: |
278+
On 15 August 2025, DigiCert will deprecate support for the legacy CNAME Delegation DCV workflow. DigiCert is transitioning to a new open-source software (OSS) domain control validation (DCV) platform designed to enhance transparency and accountability in domain validation processes. DigiCert will no longer support the legacy CNAME Delegation DCV workflow for domain control validation in the specified Azure services. [Learn more](https://learn.microsoft.com/en-us/azure/security/fundamentals/managed-tls-changes)
279+
280+
- question: |
281+
Which Azure Front Door SKUs are affected by this change?
282+
answer: |
283+
The deprecation impacts services that rely on CNAME-based validation for automated certificate issuance and renewal, including:
284+
285+
- Azure Front Door (classic)
286+
- Azure CDN from Microsoft (classic)
287+
288+
- question: |
289+
What will happen after 15 August 2025?
290+
answer: |
291+
Azure Front Door (classic) and Azure CDN from Microsoft (classic):
292+
- Will no longer support for new domain onboarding and new profile creation.
293+
- Will no longer support Azure-managed certificates.
294+
- Automation scripts for these actions will begin to fail.
295+
- Switching to managed certificates on existing domains will no longer be allowed.
296+
- Emergent renewals of managed certificates will not be possible due to the deprecation of CNAME-based validation.
297+
298+
- question: |
299+
What happens to existing managed certificates?
300+
answer: |
301+
Existing managed certificates will be automatically renewed before 15 August 2025 and remain valid until 14 April, 2026. However, any renewal required after 15 August 2025 will not be possible.
302+
303+
- question: |
304+
What actions should I take to avoid service disruption?
305+
answer: |
306+
Azure Front Door (classic)
307+
308+
- If you want to create new domains or profiles, or use Azure managed certificates, [migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/frontdoor/tier-migration) before 15 August 2025.
309+
- If you're already using Azure managed certificates on existing domains, you can either [Move to Bring Your Own Certificate (BYOC)](https://learn.microsoft.com/en-us/azure/frontdoor/front-door-custom-domain-https?tabs=powershell) or [migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/frontdoor/tier-migration) before 15 August 2025.
310+
311+
Azure CDN from Microsoft (classic)
312+
313+
- If you want to create new domains or profiles, or use Azure managed certificates, [migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/cdn/migrate-tier?toc=%2Fazure%2Ffrontdoor%2Ftoc.json) before 15 August 2025.
314+
- If you're already using Azure managed certificates on existing domains, you can either [Move to Bring Your Own Certificate (BYOC)](https://learn.microsoft.com/en-us/azure/cdn/cdn-custom-ssl?toc=%2Fazure%2Ffrontdoor%2Ftoc.json&tabs=option-1-default-enable-https-with-a-cdn-managed-certificate) or [migrate to Azure Front Door Standard or Premium](https://learn.microsoft.com/en-us/azure/cdn/migrate-tier?toc=%2Fazure%2Ffrontdoor%2Ftoc.json) before 15 August 2025.
315+
272316
- name: Billing
273317
questions:
274318
- question: |

0 commit comments

Comments
 (0)