Serialising a root certificate for Azure VPN


Below shows a code example of how to covert a certificate to a Base64 string in order to create a point to site VPN for use with Azure.

1. Create a certificate

The makecert command is only available in the Visual Studio command prompt. This location varies depending on the version of Visual Studio, for VS 2017 community the location is here 'C:\Program Files (x86)\Microsoft Visual Studio\2017\Community\Common7\Tools\VsDevCmd.bat'

 cd D:\test 

 makecert -n "CN=RootCertificate" -r -a sha256  -sv RootCertificate.pvk "RootCertificate.cer"

The private key RootCertificate.pvk can be removed from the above, however it is useful when creating client certificates from this root.

If you have left the private key in you should see the following:

Private Key Password

Click none for the basis of this test

2. Convert the certificate to a Base64 string

The rest of these steps require powershell

 function Create-Base64Certificate { 

    $CertificatePath = "D:\test\RootCertificate.cer" 

    $certificate = new-object System.Security.Cryptography.X509Certificates.X509Certificate2($CertificatePath) 

    $certificateBase64 = [system.convert]::ToBase64String($certificate.RawData) 

    $certificateBase64 >> out.txt 



3. Review contents of out.txt

You should see something similar


This Base64 string can be used when creating and uploading a root certificate to an Azure VPN.

4. Try it in an Azure Template

  "apiVersion": "2015-06-15",
  "type": "Microsoft.Network/virtualNetworkGateways",
  "name": "api-gateway-test",
  "location": "[resourceGroup().location]",
  "dependsOn": [
    "[concat("Microsoft.Network/publicIPAddresses/", parameters("gatewayPublicIPName"))]",
    "[concat("Microsoft.Network/virtualNetworks/", variables("virtualNetworkName"))]"
  "properties": {
    "ipConfigurations": [
        "properties": {
          "privateIPAllocationMethod": "Dynamic",
          "subnet": {
            "id": "[variables("gatewaySubnetRef")]"
          "publicIPAddress": {
            "id": "[resourceId("Microsoft.Network/publicIPAddresses",parameters("gatewayPublicIPName"))]"
        "name": "vnetGatewayConfig"
    "sku": {
      "name": "Basic",
      "tier": "Basic"
    "gatewayType": "Vpn",
    "vpnType": "RouteBased",
    "enableBgp": "false",
    "vpnClientConfiguration": {
      "vpnClientAddressPool": {
        "addressPrefixes": [
      "vpnClientRootCertificates": [
          "name": "TestRootCert",
          "properties": {
            "PublicCertData": "[parameters("certificateBase64String")]"