Share via


az network application-gateway ssl-profile

Manage SSL profiles of application gateway.

Commands

Name Description Type Status
az network application-gateway ssl-profile add

Add an SSL profile of the application gateway.

Core GA
az network application-gateway ssl-profile list

List the existing SSL profiles of the application gateway.

Core GA
az network application-gateway ssl-profile remove

Remove an existing SSL profile of the application gateway.

Core GA
az network application-gateway ssl-profile show

Show an existing SSL profile of the application gateway.

Core GA
az network application-gateway ssl-profile update

Update SSL profile of the application gateway.

Core GA
az network application-gateway ssl-profile wait

Place the CLI in a waiting state until a condition is met.

Core GA

az network application-gateway ssl-profile add

Add an SSL profile of the application gateway.

az network application-gateway ssl-profile add --gateway-name
                                               --name
                                               --resource-group
                                               [--cipher-suites]
                                               [--client-auth-config {0, 1, f, false, n, no, t, true, y, yes}]
                                               [--disabled-protocols]
                                               [--min-protocol-version {TLSv1_0, TLSv1_1, TLSv1_2, TLSv1_3}]
                                               [--no-wait {0, 1, f, false, n, no, t, true, y, yes}]
                                               [--policy-name {AppGwSslPolicy20150501, AppGwSslPolicy20170401, AppGwSslPolicy20170401S, AppGwSslPolicy20220101, AppGwSslPolicy20220101S}]
                                               [--policy-type {Custom, CustomV2, Predefined}]
                                               [--trusted-client-cert]

Examples

Update SSL profile for an existing application gateway.

az network application-gateway ssl-profile update --gateway-name MyAppGateway -g MyResourceGroup --name MySslProfile --client-auth-configuration False

Required Parameters

--gateway-name

Name of the application gateway.

--name

Name of the SSL profile.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

--cipher-suites

SSL cipher suites to be enabled in the specified order to application gateway. Support shorthand-syntax, json-file and yaml-file. Try "??" to show more.

--client-auth-config --client-auth-configuration

Client authentication configuration of the application gateway resource.

Accepted values: 0, 1, f, false, n, no, t, true, y, yes
--disabled-protocols --disabled-ssl-protocols

Space-separated list of protocols to disable. Support shorthand-syntax, json-file and yaml-file. Try "??" to show more.

--min-protocol-version

Minimum version of SSL protocol to be supported on application gateway.

Accepted values: TLSv1_0, TLSv1_1, TLSv1_2, TLSv1_3
--no-wait

Do not wait for the long-running operation to finish.

Accepted values: 0, 1, f, false, n, no, t, true, y, yes
--policy-name

Name of SSL policy.

Accepted values: AppGwSslPolicy20150501, AppGwSslPolicy20170401, AppGwSslPolicy20170401S, AppGwSslPolicy20220101, AppGwSslPolicy20220101S
--policy-type

Type of SSL policy.

Accepted values: Custom, CustomV2, Predefined
--trusted-client-cert --trusted-client-certificates

Array of references to application gateway trusted client certificates. Support shorthand-syntax, json-file and yaml-file. Try "??" to show more.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

--output -o

Output format.

Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
Default value: json
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

az network application-gateway ssl-profile list

List the existing SSL profiles of the application gateway.

az network application-gateway ssl-profile list --gateway-name
                                                --resource-group

Examples

List all the SSL profiles for an existing application gateway.

az network application-gateway ssl-profile list --gateway-name MyAppGateway -g MyResourceGroup

Required Parameters

--gateway-name

Name of the application gateway.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

--output -o

Output format.

Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
Default value: json
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

az network application-gateway ssl-profile remove

Remove an existing SSL profile of the application gateway.

az network application-gateway ssl-profile remove --gateway-name
                                                  --name
                                                  --resource-group
                                                  [--no-wait {0, 1, f, false, n, no, t, true, y, yes}]

Examples

Remove SSL profile for an existing application gateway.

az network application-gateway ssl-profile remove --gateway-name MyAppGateway -g MyResourceGroup --name MySslProfile

Required Parameters

--gateway-name

Name of the application gateway.

--name

Name of the SSL profile.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

--no-wait

Do not wait for the long-running operation to finish.

Accepted values: 0, 1, f, false, n, no, t, true, y, yes
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

--output -o

Output format.

Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
Default value: json
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

az network application-gateway ssl-profile show

Show an existing SSL profile of the application gateway.

az network application-gateway ssl-profile show --gateway-name
                                                --name
                                                --resource-group

Examples

Show SSL profile for an existing application gateway.

az network application-gateway ssl-profile show --gateway-name MyAppGateway -g MyResourceGroup --name MySslProfile

Required Parameters

--gateway-name

Name of the application gateway.

--name

Name of the SSL profile.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

--output -o

Output format.

Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
Default value: json
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

az network application-gateway ssl-profile update

Update SSL profile of the application gateway.

az network application-gateway ssl-profile update --gateway-name
                                                  --name
                                                  --resource-group
                                                  [--add]
                                                  [--cipher-suites]
                                                  [--client-auth-config {0, 1, f, false, n, no, t, true, y, yes}]
                                                  [--disabled-protocols]
                                                  [--force-string {0, 1, f, false, n, no, t, true, y, yes}]
                                                  [--min-protocol-version {TLSv1_0, TLSv1_1, TLSv1_2, TLSv1_3}]
                                                  [--no-wait {0, 1, f, false, n, no, t, true, y, yes}]
                                                  [--policy-name {AppGwSslPolicy20150501, AppGwSslPolicy20170401, AppGwSslPolicy20170401S, AppGwSslPolicy20220101, AppGwSslPolicy20220101S}]
                                                  [--policy-type {Custom, CustomV2, Predefined}]
                                                  [--remove]
                                                  [--set]
                                                  [--trusted-client-cert]

Examples

Update SSL profile for an existing application gateway.

az network application-gateway ssl-profile update --gateway-name MyAppGateway -g MyResourceGroup --name MySslProfile --client-auth-configuration False

Required Parameters

--gateway-name

Name of the application gateway.

--name

Name of the SSL profile.

--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

Optional Parameters

--add

Add an object to a list of objects by specifying a path and key value pairs. Example: --add property.listProperty <key=value, string or JSON string>.

--cipher-suites

SSL cipher suites to be enabled in the specified order to application gateway. Support shorthand-syntax, json-file and yaml-file. Try "??" to show more.

--client-auth-config --client-auth-configuration

Client authentication configuration of the application gateway resource.

Accepted values: 0, 1, f, false, n, no, t, true, y, yes
--disabled-protocols --disabled-ssl-protocols

Space-separated list of protocols to disable. Support shorthand-syntax, json-file and yaml-file. Try "??" to show more.

--force-string

When using 'set' or 'add', preserve string literals instead of attempting to convert to JSON.

Accepted values: 0, 1, f, false, n, no, t, true, y, yes
--min-protocol-version

Minimum version of SSL protocol to be supported on application gateway.

Accepted values: TLSv1_0, TLSv1_1, TLSv1_2, TLSv1_3
--no-wait

Do not wait for the long-running operation to finish.

Accepted values: 0, 1, f, false, n, no, t, true, y, yes
--policy-name

Name of SSL policy.

Accepted values: AppGwSslPolicy20150501, AppGwSslPolicy20170401, AppGwSslPolicy20170401S, AppGwSslPolicy20220101, AppGwSslPolicy20220101S
--policy-type

Type of SSL policy.

Accepted values: Custom, CustomV2, Predefined
--remove

Remove a property or an element from a list. Example: --remove property.list <indexToRemove> OR --remove propertyToRemove.

--set

Update an object by specifying a property path and value to set. Example: --set property1.property2=<value>.

--trusted-client-cert --trusted-client-certificates

Array of references to application gateway trusted client certificates. Support shorthand-syntax, json-file and yaml-file. Try "??" to show more.

Global Parameters
--debug

Increase logging verbosity to show all debug logs.

--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

--output -o

Output format.

Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
Default value: json
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.

az network application-gateway ssl-profile wait

Place the CLI in a waiting state until a condition is met.

az network application-gateway ssl-profile wait [--created]
                                                [--custom]
                                                [--deleted]
                                                [--exists]
                                                [--gateway-name]
                                                [--ids]
                                                [--interval]
                                                [--resource-group]
                                                [--subscription]
                                                [--timeout]
                                                [--updated]

Optional Parameters

--created

Wait until created with 'provisioningState' at 'Succeeded'.

Default value: False
--custom

Wait until the condition satisfies a custom JMESPath query. E.g. provisioningState!='InProgress', instanceView.statuses[?code=='PowerState/running'].

--deleted

Wait until deleted.

Default value: False
--exists

Wait until the resource exists.

Default value: False
--gateway-name

Name of the application gateway.

--ids

One or more resource IDs (space-delimited). It should be a complete resource ID containing all information of 'Resource Id' arguments. You should provide either --ids or other 'Resource Id' arguments.

--interval

Polling interval in seconds.

Default value: 30
--resource-group -g

Name of resource group. You can configure the default group using az configure --defaults group=<name>.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--timeout

Maximum wait in seconds.

Default value: 3600
--updated

Wait until updated with provisioningState at 'Succeeded'.

Default value: False
Global Parameters
--debug

Increase logging verbosity to show all debug logs.

--help -h

Show this help message and exit.

--only-show-errors

Only show errors, suppressing warnings.

--output -o

Output format.

Accepted values: json, jsonc, none, table, tsv, yaml, yamlc
Default value: json
--query

JMESPath query string. See http://jmespath.org/ for more information and examples.

--subscription

Name or ID of subscription. You can configure the default subscription using az account set -s NAME_OR_ID.

--verbose

Increase logging verbosity. Use --debug for full debug logs.