Application Gateway v2如何为多个Listener使用同一SSL证书?
Hey there, let's sort out this SSL certificate issue you're facing with your Application Gateway v2. The error you're seeing happens because Azure doesn't allow multiple distinct SSL certificate resources in the same gateway that use identical certificate content — even if it's a wildcard cert. The good news is you don't need duplicate certificates at all; you just need to reuse the same single wildcard certificate resource across both of your SSL listeners.
Here's how to fix this step-by-step:
1. Clean up duplicate certificate resources (if you have them)
First, head into your Application Gateway's settings under SSL certificates and delete any duplicate entries for *.sites.contoso.com. Leave only one copy of the wildcard certificate uploaded to the gateway.
2. Configure both SSL listeners to use the same existing certificate
When setting up each listener (for ports 16000 and 16001):
- For the first listener (port 16000): When prompted for an SSL certificate, select Choose an existing certificate and pick your uploaded
*.sites.contoso.comcert. Set the host name tosite1.sites.contoso.com(if you need host-based routing) and finish configuring the listener to point to its backend pool. - For the second listener (port 16001): Repeat the process, but this time select the same existing wildcard certificate (don't upload a new one). Set the host name to
site2.sites.contoso.comand link it to its separate backend pool.
If you're using Azure CLI (instead of the portal)
You can explicitly reference the same certificate resource for both listeners with commands like this:
# Create frontend ports first if you haven't az network application-gateway frontend-port create --gateway-name myAG --resource-group myRG --name port16000 --port 16000 az network application-gateway frontend-port create --gateway-name myAG --resource-group myRG --name port16001 --port 16001 # Create first SSL listener (uses existing wildcard cert) az network application-gateway http-listener create \ --gateway-name myAG \ --resource-group myRG \ --name listener-16000 \ --frontend-ip appGatewayFrontendIP \ --frontend-port port16000 \ --ssl-cert my-wildcard-cert-resource-name \ --host-name site1.sites.contoso.com # Create second SSL listener (reuses the same cert) az network application-gateway http-listener create \ --gateway-name myAG \ --resource-group myRG \ --name listener-16001 \ --frontend-ip appGatewayFrontendIP \ --frontend-port port16001 \ --ssl-cert my-wildcard-cert-resource-name \ --host-name site2.sites.contoso.com
Why your initial attempt might have failed
It sounds like when you tried to "reference the same certificate," you might have accidentally initiated a new certificate upload instead of selecting the existing one from the gateway's certificate library. Double-check the portal UI to make sure you're choosing the existing certificate option rather than uploading a duplicate.
This approach works because your wildcard certificate *.sites.contoso.com is valid for all subdomains under sites.contoso.com, so both site1 and site2 are covered. Azure fully supports using a single SSL certificate resource across multiple listeners as long as the certificate matches the listener's host name.
内容的提问来源于stack exchange,提问作者user3012708

