we are getting a TLS handshake failure from Azure App Service since the certificate rotated, the response size now exceeds the buffer size in our firmware

Iain Warner Admin 20 Reputation points
2026-09-24T07:22:07.0633333+00:00

Hostname: prod-afdps-airception.azurewebsites.net

Protocol: TLS 1.2

Client TLS library: Mbed TLS

Maximum inbound TLS content length: 6144 bytes

Current certificate-chain DER size: 6793 bytes before TLS framing

Device error: mbedtls_ssl_handshake returned -0x7100

Failure occurs before certificate verification callbacks

Microsoft login TLS connections from the same device succeed

can the App Service front end can either:

  • serve a shorter valid chain for this endpoint;
  • provide an alternative chain compatible with DigiCert Global Root G2;
  • or temporarily roll back the certificate-chain change that triggered the failure.
Azure App Service
Azure App Service

Azure App Service is a service used to create and deploy scalable, mission-critical web apps.

0 comments No comments

Answer accepted by question author
Taz 10,046 Reputation points MVP Volunteer Moderator
2026-09-27T13:35:30.8666667+00:00

Hi Iain,

The failure is consistent with the Mbed TLS client being unable to hold the certificate handshake message. Your client allows only 6144 bytes, while the certificate chain is 6793 bytes before TLS framing. Mbed TLS documents that the TLS handshake can require a larger buffer when certificate data is sent, and the handshake fails when the configured buffer is too small.

Also, prod-afdps-airception.azurewebsites.net is an App Service default *.azurewebsites.net hostname. Those certificates are managed by Azure and can be rotated; Microsoft explicitly recommends that clients not depend on a fixed default App Service certificate or certificate chain.

So the practical fix is to increase the Mbed TLS incoming handshake/content buffer to at least 8 KB, preferably 16 KB, rather than relying on Azure to serve a shorter chain.

There is no supported App Service setting to select a shorter certificate chain or force a particular DigiCert chain for the default azurewebsites.net certificate.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Oldest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.