Azure Application Gateway是否可实现FIPS合规?
Great question—let’s walk through this clearly, based on real-world experience and Azure’s current service constraints:
Core Conclusion
As you suspected, Azure Application Gateway cannot natively meet FIPS 140-2 compliance requirements today, due to a conflicting constraint between FIPS standards and the service’s SSL configuration rules. But there are practical workarounds to achieve end-to-end FIPS compliance in your architecture.
Why the Native Conflict Exists
You’ve hit on the key issue, which boils down to two non-negotiable rules:
- FIPS 140-2 prohibits stored encryption keys (like .pfx files) from being password-protected—this violates the standard’s requirements for secure key storage and management.
- Azure Application Gateway enforces that all SSL certificates uploaded (or retrieved from Azure Key Vault) must be password-protected .pfx files. This is a hardcoded requirement of the service’s SSL termination logic, with no way to bypass it directly.
Workarounds to Achieve FIPS Compliance
If FIPS 140-2 is a mandatory requirement, here are the most reliable ways to structure your architecture:
- Front with Azure Front Door
Azure Front Door is natively FIPS 140-2 compliant and supports SSL termination using non-password-protected keys. Route all external traffic through Front Door first (handling the FIPS-compliant SSL handshake), then forward the decrypted traffic to your Application Gateway. The gateway can then focus on backend routing/load balancing without needing to handle public-facing SSL (or you can use internal, non-FIPS certificates for backend communication, since the public SSL layer is already compliant). This is the most widely adopted solution for this scenario. - Switch to Azure API Management (APIM) for API-centric workloads
If your use case involves API routing and management, APIM is fully FIPS 140-2 compliant and can replace many of Application Gateway’s core functions (load balancing, SSL termination, routing rules). It supports direct use of FIPS-compliant key storage, eliminating the .pfx password conflict entirely.
Important Note
There is no official way to make the Application Gateway itself FIPS-compliant at this time. Microsoft’s service compliance documentation does not list Application Gateway as a FIPS 140-2 validated service, and the .pfx password requirement is not configurable.
内容的提问来源于stack exchange,提问作者dcembree83

