How to troubeshoot 403 error when using Trusted Signing

Murray McCulligh 20 Reputation points
2025-06-09T20:31:31.4633333+00:00

We recently created a new Identity Validation and created a new certificate profile to use it but cannot sign correctly with it. We get a 403 when requesting for it with a service principal with a Trusted Signing Certificate Profile Signer role. The old certificate profile works correctly, but the new one fails. It cannot be an authentication issue since the service principal is the same and the two profiles are in the same Trusted Signing Account. How do we troubleshoot this? I created a diagnostic setting that used a storage account, but nothing is ever written to it.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

3 answers

Sort by: Most helpful
  1. Murray McCulligh 20 Reputation points
    2025-06-17T20:55:14.1233333+00:00

    Microsoft has helped fix the underlying issue, which seems to have been caused back when we were part of the preview. Our Trusted Signing Account is listed as being in US West 2. But the account URI didn't match, it was US East. The new certificate profile created was thus not accessible via the account URI unlike the older ones where.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. Meha-MSFT 2,460 Reputation points Microsoft Employee Moderator
    2025-06-13T18:52:53.5666667+00:00

    We are looking into this and will get back. Also, have you tried configring EventHub does that work to give you some data.

    Was this answer helpful?


  3. Meha-MSFT 2,460 Reputation points Microsoft Employee Moderator
    2025-06-11T16:40:23.68+00:00

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.