Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
Hi Iain,
The failure is consistent with the Mbed TLS client being unable to hold the certificate handshake message. Your client allows only 6144 bytes, while the certificate chain is 6793 bytes before TLS framing. Mbed TLS documents that the TLS handshake can require a larger buffer when certificate data is sent, and the handshake fails when the configured buffer is too small.
Also, prod-afdps-airception.azurewebsites.net is an App Service default *.azurewebsites.net hostname. Those certificates are managed by Azure and can be rotated; Microsoft explicitly recommends that clients not depend on a fixed default App Service certificate or certificate chain.
So the practical fix is to increase the Mbed TLS incoming handshake/content buffer to at least 8 KB, preferably 16 KB, rather than relying on Azure to serve a shorter chain.
There is no supported App Service setting to select a shorter certificate chain or force a particular DigiCert chain for the default azurewebsites.net certificate.