Artifact signing stopped working

Prakash 0 Reputation points
2026-04-14T05:34:12.38+00:00

Hi,

We are using trusted/artifact signing for past 2 years it worked without issues. But for the last few days we are getting the below error,

Submitting digest for signing...
Unhandled managed exception
Azure.RequestFailedException: Service request failed.
Status: 403 (Forbidden)

Headers:
Date: Tue, 14 Apr 2026 04:09:45 GMT
Connection: keep-alive
Server: Kestrel
Strict-Transport-Security: REDACTED
Content-Length: 0

   at Azure.CodeSigning.CertificateProfileRestClient.SignAsync(String codeSigningAccountName, String certificateProfileName, SignRequest body, String xCorrelationId, String clientVersion, CancellationToken cancellationToken)
   at Azure.CodeSigning.CertificateProfileClient.StartSignAsync(String codeSigningAccountName, String certificateProfileName, SignRequest body, String xCorrelationId, String clientVersion, CancellationToken cancellationToken)
   at Azure.CodeSigning.Dlib.Core.DigestSigner.SignAsync(UInt32 algorithm, Byte[] digest, SafeFileHandle safeFileHandle, CancellationToken cancellationToken)
   at Azure.CodeSigning.Dlib.Core.DigestSigner.Sign(UInt32 algorithm, Byte[] digest, SafeFileHandle safeFileHandle)
   at AuthenticodeDigestSignExWithFileHandleManaged(_CRYPTOAPI_BLOB* pMetadataBlob, UInt32 digestAlgId, Byte* pbToBeSignedDigest, UInt32 cbToBeSignedDigest, Void* hFile, _CRYPTOAPI_BLOB* pSignedDigest, _CERT_CONTEXT** ppSignerCert, Void* hCertChainStore)

SignTool Error: An unexpected internal error has occurred.
Error information: "Error: SignerSign() failed." (-2147467259/0x80004005)

Below is the screen shot of the certificate profile it is still active but the date seems expired. Not sure why it is not automatically renews. Is there any reason for that?

enter image description here[Updated]

The artifact signing certificate profile account was created almost 1.5 years back. The country is India.

Saw a warning message in the azure portal that "Artifact Signing is currently available to organizations in the USA, Canada, European Union & United Kingdom.". Seems that was there for the last one year.

Is it suddenly enforced for the existing accounts as well? thats why the auto renewal of public trust profiles are blocked? It will be great to have a concrete answer from the Microsoft side so that we can move and look for other alternates.

Note: I also have a certificate profile of type "Public Trust Test" where it certificate is not expired and it is working as expected but it is a test certificate. This indicates there are no permission or endpoint url issues.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

3 answers

Sort by: Most helpful
  1. Prakash 0 Reputation points
    2026-04-22T09:42:14.3+00:00

    Got an update from azure! They confirmed it was one time issue and fixed the renewal. Also they confirmed that the geo restriction is not applicable to the existing customers.

    Was this answer helpful?


  2. Prakash 0 Reputation points
    2026-04-14T06:04:39.2333333+00:00

    The artifact signing certificate profile account was created almost 1.5 years back. The country is India.

    Saw a warning message in the azure portal that "Artifact Signing is currently available to organizations in the USA, Canada, European Union & United Kingdom.". Seems that was there for the last one year.

    Is it suddenly enforced for the existing accounts as well? thats why the auto renewal of public trust profiles are blocked? It will be great to have a concrete answer from the Microsoft side so that we can move and look for other alternates.

    Note:
    I also have a certificate profile of type "Public Trust Test" where it certificate is not expired and it is working as expected but it is a test certificate. This indicates there are no permission or endpoint url issues.

    Was this answer helpful?

    0 comments No comments

  3. AI answer

    2026-04-14T05:34:34.5666667+00:00

    The 403 (Forbidden) with SignerSign() failed indicates that Artifact Signing is rejecting the sign request, not that SignTool itself is broken. In the context of Artifact Signing, common 403 causes are:

    • Subscription or account not in a valid state
    • Identity no longer having the Artifact Signing Certificate Profile Signer role
    • Endpoint / profile metadata mismatch
    • Certificate profile not in an active/valid state from the service’s perspective

    For Artifact Signing specifically, the documented mitigations for 403 are:

    1. Verify the Azure subscription status is Registered.
    2. Confirm that the identity used to sign (user, service principal, or managed identity) still has the Artifact Signing Certificate Profile Signer role on the resource group or subscription that contains the Artifact Signing account.
    3. Check that the CodeSigningAccountName and CertificateProfileName in the metadata.json file exactly match the Artifact Signing account and certificate profile names.
    4. Ensure the dlib path and dlib version are correct and supported, and that the recommended Windows SDK and .NET versions are installed.
    5. Confirm that the certificate profile’s Status is Active and that the identity validation for that profile shows Completed.
    6. Verify that the Endpoint in metadata.json matches the region where the Artifact Signing account and certificate profile were created. A region/endpoint mismatch commonly produces 403 and an internal SignerSign() failure.
    7. If using Private Trust, ensure the same user object ID that calls Get-AzCodeSigningRootCert is the one doing the signing and that it has the Artifact Signing Certificate Profile Signer role.
    8. Try the signing operation from a different VM or machine to rule out local or network issues reaching the Artifact Signing endpoint.

    Regarding the expiry date shown in the portal: Artifact Signing certificates themselves are short-lived (three-day validity) and are managed by the service; time stamping is required so signatures remain valid beyond that period. The service documentation does not describe automatic renewal behavior for the certificate profile’s portal “Expiry date” field, and it does not expose the underlying Authenticode certificate to the customer. If the profile shows an expiry date in the past while the status is still Active but signing returns 403, this aligns with the general guidance that the profile or its validation/state in the service must be checked and, if necessary, recreated.

    Because Artifact Signing resources cannot be migrated across subscriptions or tenants and must be recreated when those change, if there has been any change to subscription or tenant, all Artifact Signing resources (including certificate profiles) must be recreated.

    Actionable steps:

    1. In Azure portal, open the subscription that contains the Artifact Signing account and confirm the subscription is Registered.
    2. On the Artifact Signing account and certificate profile:
      • Confirm Status is Active.
      • Confirm identity validation status is Completed.
    3. In Access control (IAM) for the resource group or subscription, verify that the signing identity has the Artifact Signing Certificate Profile Signer role.
    4. Open the metadata.json used by SignTool and verify:
      • Endpoint matches the region of the Artifact Signing account.
      • CodeSigningAccountName and CertificateProfileName exactly match the portal values.
    5. Ensure the latest Azure.CodeSigning.Dlib.dll, Windows SDK, .NET runtime, and C++ Redistributables are installed as required.
    6. If all of the above are correct and the profile still shows a past expiry date with 403 responses, create a new certificate profile in the same Artifact Signing account, update metadata.json to point to the new profile, and test signing again.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.