I have APIM exposed to the web using a public DNS and publicly signed TLS cert for mydomain.com.
I want to terminate the external TLS at APIM, and route traffic to various internal services. So far so good. But I want to encrypt the traffic internally as well. So I created a self-signed certificate in keyvault (CN=*.myinternalnetwork.com), and am creating private DNS records for my various internal services (service1.myinternalnetwork.com, service2.myinternalnetwork.com, etc.) pointing to the internal IP addresses of the services. The services are presenting my self-signed cert. I want to configure APIM now to trust that certificate so I'll have end-to-end encryption.
Reading the docs here seems to indicate I have to turn off certificate chain validation to use self-signed certs: https://docs.microsoft.com/en-us/azure/api-management/api-management-howto-mutual-certificates#self-signed-certificates
Am I reading it correctly? Can I not just add the self-signed cert to APIM's trust store? Thanks.