More Info:

Ensure that Certificate Transparency feature is enabled for all Azure Key Vault SSL/TLS certificates in order to adhere to best practices. Certificate Transparency (CT) is a new Internet standard that addresses the concerns about mis-issued certificates by making the Transport Layer Security (TLS) ecosystem publicly auditable.

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the Certificate Transparency misconfiguration in Azure using Azure console, please follow the below steps:

  1. Login to Azure portal (https://portal.azure.com/)
  2. Navigate to the App Service for which you want to enable Certificate Transparency.
  3. Click on “TLS/SSL settings” under the “Settings” section.
  4. Scroll down to the “Certificate Transparency” section.
  5. Toggle the “Certificate Transparency” switch to “On” position.
  6. Click on “Save” to save the changes.

After following the above steps, Certificate Transparency will be enabled for the App Service in Azure.

Additional Reading: