When you generate a key in Azure Key Vault it is a self-signed key, it is not signed by any CA.
What CA signs certificates when using Azure Key Vault with HSM to generate & store application PKI keys and certificates?
Marcus Serrao
Reputation point
Hi. Can anyone tell me what CA is used when I generate keys and get them signed within the Azure Key Vault? Also, do I have the ability to stand up a subordinate CA in Azure, leveraging Azure Key Vault with HSM to store my CA keys and where the sub CA keys are signed by an on-premise offline root CA? thanks! Marcus