Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_first
powershell_heavy
windows_tools
missing_linux_example
Summary
The documentation page demonstrates a Windows bias by presenting Windows-specific instructions, examples, and code samples first and in greater detail. Windows certificate store usage is explained thoroughly with C# and Java code, while Linux examples are limited to C# file loading and lack parity in other languages. References to Windows tools and patterns (certificate store, environment variables, user profile loading) are frequent, while Linux equivalents are only briefly mentioned or deferred to external documentation. Non-Windows languages (Node.js, PHP, Python, Java) are not given direct Linux examples.
Recommendations
  • Provide Linux-first or parallel examples for all major languages (C#, Java, Node.js, PHP, Python) showing how to load certificates from files or environment variables.
  • Expand Linux-specific instructions, including how to use certificate files and environment variables in common Linux application stacks.
  • Add explicit Linux code samples for Java, Node.js, PHP, and Python, not just C#.
  • Balance explanations of certificate storage and access patterns between Windows and Linux, including container scenarios.
  • Reference Linux tools and patterns (e.g., OpenSSL, file permissions, environment variables) alongside Windows tools.
  • Ensure that instructions for setting app settings and accessing certificates are equally clear for Linux environments.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-02-12 00:00 #237 in_progress Clean Clean
2026-02-11 00:00 #233 in_progress Clean Clean
2026-02-10 00:00 #229 completed Biased Biased
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Clean Clean
2026-01-11 00:00 #95 cancelled Clean Clean
2026-01-10 00:00 #92 completed Clean Clean
2026-01-09 00:00 #87 cancelled Clean Clean
2026-01-08 00:00 #84 in_progress Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-29 18:00 #48 cancelled Biased Biased
2025-12-22 00:00 #24 cancelled Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean

Flagged Code Snippets

To make all your certificates accessible, set the value to `*`.

When `WEBSITE_LOAD_CERTIFICATES` is set to `*`, all previously added certificates are accessible to application code. If you add a certificate to your app later, restart the app to make the new certificate accessible to your app. For more information, see [Update or renew a certificate](#update-or-renew-a-certificate).

## Load certificates in Windows apps

The `WEBSITE_LOAD_CERTIFICATES` app setting makes the specified certificates accessible to your Windows hosted app in the Windows certificate store, in [Current User\My](/windows-hardware/drivers/install/local-machine-and-current-user-certificate-stores).

In C# code, you access the certificate by using the certificate thumbprint. The following code loads a certificate with the thumbprint `E661583E8FABEF4C0BEF694CBC41C28FB81CD870`.

For languages that don't support or offer insufficient support for the Windows certificate store, see [Load a certificate from a file](#load-a-certificate-from-a-file).

## Load a certificate from a file

If you need to load a certificate file that you upload manually, it's better to upload the certificate by using [File Transfer Protocol Secure (FTPS)](deploy-ftp.md) instead of [Git](deploy-local-git.md), for example. Keep sensitive data like a private certificate out of source control.

ASP.NET and ASP.NET Core on Windows must access the certificate store even if you load a certificate from a file. To load a certificate file in a Windows .NET app, load the current user profile with the following command in <a target="_blank" href="https://shell.azure.com" >Cloud Shell</a>:

 
### [Windows](#tab/windows)

The following C# example shows how to load a public certificate in a .NET Framework app in a Windows Server Core container.

In Java code, you access the certificate from the `Windows-MY` store by using the **Subject Common Name** field. For more information, see [Public key certificate](https://en.wikipedia.org/wiki/Public_key_certificate). The following code shows how to load a private key certificate:

To see how to load a TLS/SSL certificate from a file in Node.js, PHP, Python, or Java, see the documentation for the respective language or web platform.

## Load certificates in Linux/Windows containers

The `WEBSITE_LOAD_CERTIFICATES` app setting makes the specified certificates accessible to your Windows or Linux custom containers (including built-in Linux containers) as files. The files are found under the following directories:

| Container platform | Public certificates | Private certificates |
| - | - | - |
| Windows container | `C:\appservice\certificates\public` | `C:\appservice\certificates\private` |
| Linux container | `/var/ssl/certs` | `/var/ssl/private` |

The certificate file names are the certificate thumbprints.

> [!NOTE]
> App Service injects the certificate paths into Windows containers as the following environment variables: `WEBSITE_PRIVATE_CERTS_PATH`, `WEBSITE_INTERMEDIATE_CERTS_PATH`, `WEBSITE_PUBLIC_CERTS_PATH`, and `WEBSITE_ROOT_CERTS_PATH`. It's better to reference the certificate path with the environment variables instead of hardcoding the certificate path, in case the certificate paths change in the future.
>

In addition, [Windows Server Core and Windows Nano Server containers](configure-custom-container.md#supported-parent-images) load the certificates into the certificate store automatically, in `LocalMachine\My`. To load the certificates, follow the same pattern as shown in [Load certificates in Windows apps](#load-certificates-in-windows-apps). For Windows Nano-based containers, use the file paths as shown in [Load a certificate from a file](#load-a-certificate-from-a-file).

### [Linux](#tab/linux)

The following C# code shows how to load a public certificate in a Linux app.

The following C# example shows how to load a public certificate in a .NET Core app in a Windows Server Core or Windows Nano Server container.