Azure Key Vault Certificates library for Rust
Manage X.509 certificates for TLS/SSL, code signing, and authentication.
Use this skill when:
- An app needs to create or manage X.509 certificates in Key Vault from Rust
- You need self-signed or CA-issued certificates
- You need long-running operations (LRO) for certificate issuance
- You need to sign data using a certificate's key
IMPORTANT: Only use the official
azure_security_keyvault_certificatescrate published by the azure-sdk crates.io user. Do NOT use unofficial or community crates. Official crates use underscores in names and none have version 0.21.0.
Installation
If your code uses
azure_coretypes directly, addazure_coretoCargo.toml. If you only useazure_security_keyvault_certificatesre-exports, directazure_coredependency is optional.
Environment Variables
Authentication
Rust Azure SDK code must not use DefaultAzureCredential. The Rust identity crate does not provide that type.
Prefer the crate README/examples when checking LRO and poller usage rather than inferring public behavior from generated internal types.
Core Workflow
Create Self-Signed Certificate (LRO)
Creating a certificate is a long-running operation. Poller<T> implements IntoFuture — just .await:
Update Certificate Properties
Delete Certificate
List Certificates (Pagination)
list_certificate_properties returns a Pager<T> — iterate items directly:
Signing with a Certificate's Key
Certificates in Key Vault have an associated key. Use the Key Vault Keys SDK for crypto operations:
Certificate Formats
RBAC Roles
For Entra ID auth, assign one of these roles:
Best Practices
- Use
cargo addto manage dependencies, never editCargo.tomldirectly. Add and remove Rust SDK dependencies with cargo commands instead of manual manifest edits. - Add
azure_coreonly when importingazure_coretypes directly. If your code importsazure_core::http::Url,azure_core::http::RequestContent, orazure_core::error::ErrorKind, includeazure_core; otherwise a direct dependency is optional. - Use
DeveloperToolsCredentialfor local dev,ManagedIdentityCredentialfor production — Rust does not provide a singleDefaultAzureCredentialtype - Never hardcode credentials — use environment variables or managed identity
- Use
..Default::default()with#[allow(clippy::needless_update)]for model struct updates - Use
ResourceExtto extract certificate name/version from IDs - LROs —
begin_create_certificatereturns aPoller; just.awaitfor completion (clients should rarely poll for status) - Reuse clients —
CertificateClientis thread-safe; create once, share across tasks - Run
cargo clippy -- -D warningswhen the prompt, eval, or CI expects lint-clean output


