Register the certificate chain (BYOC)
Step 4 of 5 in Connect Azure KMS with BYOK and BYOC.
Register the chain with kind: key_certificate_chain, source: stored_public_material and
linkedKeyAlias set to the key alias from the previous step. Supply the leaf followed by any
intermediates, each DER encoded and base64 encoded. A certificate object that Azure already holds can
be registered by reference instead.
Read everything back before selecting it for an issuer. The reference shows what was registered, the chain read shows what a relying party will receive, and the trusted-certificate read confirms the stored public material.
Do not derive a chain from a single leaf or a key alias from a certificate name. When the chain does not match the key, x5c-signed credentials fail verification even though signing itself succeeds.
Next
Continue with step 5, Remove references safely.