Hi,
We are using trusted/artifact signing for past 2 years it worked without issues. But for the last few days we are getting the below error,
Submitting digest for signing...
Unhandled managed exception
Azure.RequestFailedException: Service request failed.
Status: 403 (Forbidden)
Headers:
Date: Tue, 14 Apr 2026 04:09:45 GMT
Connection: keep-alive
Server: Kestrel
Strict-Transport-Security: REDACTED
Content-Length: 0
at Azure.CodeSigning.CertificateProfileRestClient.SignAsync(String codeSigningAccountName, String certificateProfileName, SignRequest body, String xCorrelationId, String clientVersion, CancellationToken cancellationToken)
at Azure.CodeSigning.CertificateProfileClient.StartSignAsync(String codeSigningAccountName, String certificateProfileName, SignRequest body, String xCorrelationId, String clientVersion, CancellationToken cancellationToken)
at Azure.CodeSigning.Dlib.Core.DigestSigner.SignAsync(UInt32 algorithm, Byte[] digest, SafeFileHandle safeFileHandle, CancellationToken cancellationToken)
at Azure.CodeSigning.Dlib.Core.DigestSigner.Sign(UInt32 algorithm, Byte[] digest, SafeFileHandle safeFileHandle)
at AuthenticodeDigestSignExWithFileHandleManaged(_CRYPTOAPI_BLOB* pMetadataBlob, UInt32 digestAlgId, Byte* pbToBeSignedDigest, UInt32 cbToBeSignedDigest, Void* hFile, _CRYPTOAPI_BLOB* pSignedDigest, _CERT_CONTEXT** ppSignerCert, Void* hCertChainStore)
SignTool Error: An unexpected internal error has occurred.
Error information: "Error: SignerSign() failed." (-2147467259/0x80004005)
Below is the screen shot of the certificate profile it is still active but the date seems expired. Not sure why it is not automatically renews. Is there any reason for that?
[Updated]
The artifact signing certificate profile account was created almost 1.5 years back. The country is India.
Saw a warning message in the azure portal that "Artifact Signing is currently available to organizations in the USA, Canada, European Union & United Kingdom.". Seems that was there for the last one year.
Is it suddenly enforced for the existing accounts as well? thats why the auto renewal of public trust profiles are blocked? It will be great to have a concrete answer from the Microsoft side so that we can move and look for other alternates.
Note: I also have a certificate profile of type "Public Trust Test" where it certificate is not expired and it is working as expected but it is a test certificate. This indicates there are no permission or endpoint url issues.