Azure / Azure/azure-cli

az webapp config ssl create - Doesn't support child DNS zone

Open
#30,100 7 comments 1 reaction 1 assignee Assigned to @yutangl View on GitHub
act-observability-squad app-service-certs-domains Auto-Assign bug customer-reported Service Attention Web Apps
Dominant language
Python
Stars
4.6k
Forks
3.5k
Avg merge
3d 2h
Merged PRs (30d)
60

Description

### Describe the bug

I have the following DNS setup:
1. a main DNS zone for my domain, example.com
2. A child zone for the main DNS zone: qa.example.com

I create an A record in the child zone - @ and then the IP of the webapp, aswell as the asuid txt record for domain validation.

When running;
```
az webapp config ssl create --resource-group myresourcegroup --name mywebapp --hostname qa.example.com
```

It fails with:
Properties.CanonicalName is invalid. Not found CNAME directly pointing to *.azurewebsites.net. Current CNAME record of the hostname qa.example.com is empty.

It should be possible to specify the validation method, so that you can specify ARecord. This is currently possible in azure container apps with `az containerapp hostname bind`

### Related command

az webapp config ssl create

### Errors

Sensitive information removed (removed the child DNS zone with example.com):
```json
{
"Code": "BadRequest",
"Message": "Properties.CanonicalName is invalid. Not found CNAME directly pointing to *.azurewebsites.net. Current CNAME record of the hostname qa.example.com is empty.",
"Target": null,
"Details": [
{
"Message": "Properties.CanonicalName is invalid. Not found CNAME directly pointing to *.azurewebsites.net. Current CNAME record of the hostname qa.example.com is empty."
},
{
"Code": "BadRequest"
},
{
"ErrorEntity": {
"ExtendedCode": "51021",
"MessageTemplate": "{0} is invalid. {1}",
"Parameters": [
"Properties.CanonicalName",
"Not found CNAME directly pointing to *.azurewebsites.net. Current CNAME record of the hostname qa.example.com is empty."
],
"Code": "BadRequest",
"Message": "Properties.CanonicalName is invalid. Not found CNAME directly pointing to *.azurewebsites.net. Current CNAME record of the hostname qa.example.com is empty."
}
}
],
"Innererror": null
}
```

### Issue script & Debug output

I think it's not needed.

### Expected behavior

As an ARecord is defined in the child DNS zone, it should be able to validate and bind the certifcate. It defaults to cname, which seems incorrect.

### Environment Summary

azure-cli 2.65.0

core 2.65.0
telemetry 1.1.0

Extensions:
account 0.2.5

Dependencies:
msal 1.31.0
azure-mgmt-resource 23.1.1

Python location 'C:\Program Files\Microsoft SDKs\Azure\CLI2\python.exe'
Python (Windows) 3.11.8 (tags/v3.11.8:db85d51, Feb 6 2024, 22:03:32) [MSC v.1937 64 bit (AMD64)]

### Additional context

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.