You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure CLI为应用网关后端HTTPS设置添加授权证书

用Azure CLI实现应用网关后端HTTPS设置添加授权证书的操作

我来帮你搞定这个问题——你用PowerShell那行命令实现的功能,Azure CLI确实没有直接对应AuthenticationCertificates的参数,但可以通过分步骤操作达成同样的效果,具体流程如下:

步骤1:上传授权证书到应用网关(若未上传)

首先需要把你的授权证书(.cer格式)上传到目标应用网关的授权证书集合中,执行以下命令:

az network application-gateway auth-cert create \
  --gateway-name <你的应用网关名称> \
  --name <授权证书的自定义名称> \
  --resource-group <资源组名称> \
  --cert-file <本地证书文件路径,例如./my-auth-cert.cer>

步骤2:获取授权证书的资源ID(可选,也可直接用名称)

为了后续引用更方便,你可以把证书的资源ID存入变量:

auth_cert_id=$(az network application-gateway auth-cert show \
  --gateway-name <你的应用网关名称> \
  --name <授权证书的自定义名称> \
  --resource-group <资源组名称> \
  --query id -o tsv)

步骤3:创建后端HTTPS设置并关联授权证书

现在就可以创建后端HTTPS设置,通过--auth-certs参数关联刚才的授权证书,这一步就对应你PowerShell命令里的-AuthenticationCertificates $authcert:

az network application-gateway backend-http-settings create \
  --name setting01 \
  --gateway-name <你的应用网关名称> \
  --resource-group <资源组名称> \
  --port 443 \
  --protocol Https \
  --cookie-based-affinity Enabled \
  --auth-certs $auth_cert_id

如果你不想用ID,也可以直接替换成证书的自定义名称,比如--auth-certs <授权证书的自定义名称>,效果完全一致。

额外说明:更新已存在的后端HTTPS设置

如果是要给已有的后端HTTPS设置添加授权证书,改用update命令即可:

az network application-gateway backend-http-settings update \
  --name setting01 \
  --gateway-name <你的应用网关名称> \
  --resource-group <资源组名称> \
  --auth-certs $auth_cert_id

内容的提问来源于stack exchange,提问作者BlindSniper

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:14:22