We have tried to rewrite the headers with a Custom Header name X-ARR-ClientCert with value in App gateway using route-path based rule and without SSL Profile configured as we do not have idea on impact it would be create in a case of attaching the SSL profile to listener
As per your scenario, we have a single listener to our APIM instance configured in Azure App Gateway. In a case of configuring the SSL Profile and attaching to the Listener.
enter image description here" />
Application Gateway supports certificates issued from both public and privately established certificate authorities. Therefore, CA certificates must be uploaded. Ensure that the client certificate's immediate issuer is verified and only permits that issuer to be trusted by your application gateway.
By default, this option is disabled, but if you want to use the application Gateway to validate the client, you can enable it through the portal.
enter image description here" />
enter image description here" />
To know more in detail, check these references.