Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
Failed to create App Service Managed Certificate: Pending managed certificate failed: Website not available for updating validation token
I am attempting to add a managed app service certificate to a Blazor windows webassembly application and getting this error.
The DNS is provided by CloudFlare
Things I have checked:
- The app is publically accessible with no access restrictions.
- The CAA record 0 issue digicert.com record present on both the root domain and the subdomain.
- There also used to be a Managed cert on this app, the auto renewal failed due to the
Azure App Service
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-21T15:56:57.6033333+00:00 Hi @Dan Piccot
Thanks for reaching us regarding the issue Pending managed certificate failed we started checking on this we will update our suggestions ASP.
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-21T16:25:39.69+00:00 Hi @Dan Piccot
Thank you for reaching us regarding the "Pending managed certificate failed" issue.
The error "Pending managed certificate failed: Website not available for updating validation token" means Azure is unable to verify your domain. This is often due to recent changes (July 2025) that require HTTP-based validation, which can be affected by DNS proxying (such as Cloudflare), access restrictions, or outdated certificate bindings.
To resolve this, please:
- Temporarily disable the Cloudflare proxy by setting the DNS record to "DNS Only" during validation.
- Make sure your custom domain is accessible over HTTP by disabling "HTTPS Only" in App Service > Configuration > General settings.
- Delete any old managed certificates before creating a new one.
- Check that http://<your-subdomain>/.well-known/pki-validation/ is accessible (using a browser or curl) without any restrictions.
Reference:
https://learn.microsoft.com/en-us/azure/app-service/configure-ssl-certificate?tabs=apex%2Crbac%2Caz…
After these steps, retry creating the certificate. Once successful, re-enable "HTTPS Only" and CloudFlare proxy. If issues persist, let us know—we can guide you
Please "upvote" if the information helped you. This will help us and others in the community as well.
-
Dan Piccot • 0 Reputation points
2025-10-21T17:22:22.8966667+00:00 There were no other managed certs related to this domain left (had been already removed after auto renewal failed).
After removing the HTTPS only setting, and verifying that the the address supplied is accessible (it redirects to the 404 page) via HTTP, I am still having the same issue.
The only proxied DNS record is an unrelated website at the root domain, this proxy can be removed tomorrow morning if you think it would cause an issue.
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-22T09:22:45.4433333+00:00 Hi @Dan Piccot
Thank you for the update. The error suggests that Azure is unable to verify your domain because the validation token isn't working. This might be caused by a 404 redirect or an unrelated proxied DNS record on the root domain.
To fix this:
- Add a simple static HTML file (like index.html) to your app’s root directory. This will provide a basic HTTP response at http://<your-subdomain>/.well-known/pki-validation/ and should resolve the 404 issue.
- Remove any unrelated proxied DNS record from the root domain tomorrow morning, then wait 5-10 minutes for the DNS changes to take effect.
- Try creating the certificate again using App Service > Custom domains > TLS/SSL binding. Check http://<your-subdomain>/.well-known/pki-validation/fileauth.txt—if it works, a token will show up within 5-15 minutes.
Reference:
After completing these steps, you can remove the HTML file and turn "HTTPS Only" and the CloudFlare proxy back on. If the problem persists, let us know so we can help with the Azure CLI or review your network settings.
Please "upvote" if the information helped you. This will help us and others in the community as well.
-
Dan Piccot • 0 Reputation points
2025-10-22T14:07:36.4133333+00:00 Following up.
We have removed all proxied domains from the cloudflare account and set them to DNS only to be safe. The webapp is now also just a blank index.html page.
Hitting the domain with
curl -i http://app.nimbl.ad/.well-known/pki-validation/fileauth.txt
still only returns a 404 during and after the validation process, with the validation process hitting the same error.
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-22T16:20:54.5633333+00:00 Hi @Dan Piccot
Thank you for the update. The persistent 404 error at http://app.nimbl.ad/.well-known/pki-validation/fileauth.txt suggests Azure is unable to place or serve the validation token for the managed certificate. Here are the next steps to resolve this:
- Run Azure Diagnostics:
- In the Azure portal, go to your App Service > Diagnose and solve problems.
- Run Configuration and Management and SSL and Domains diagnostics to identify configuration or file system issues.
- Follow any recommended fixes or share the output for further assistance.
- Check. well-known Path Handling:
- Please verify that your Blazor application does not restrict access to the /.well-known/pki-validation/ path as a result of routing or rewrite configurations.
- Add a static fileauth.txt with dummy content (e.g., "test") in wwwroot/.well-known/pki-validation/. Test access via curl -i http://app.nimbl.ad/.well-known/pki-validation/fileauth.txt.
- If access is restricted, please add an exception for .well-known in the web.config file.
<configuration> <system.webServer> <rewrite> <rules> <rule name="Allow well-known" stopProcessing="true"> <match url="\.well-known/.*" /> <action type="None" /> </rule> </rules> </rewrite> </system.webServer> </configuration>
- Please ensure that there are no redirects present.
- Please verify that HTTPS Only is disabled in the Configuration > General settings section.
- Please ensure that your Blazor application's client-side routing does not redirect requests to /.well-known. If necessary, consider temporarily disabling routing to prevent this behavior.
- Please verify both the DNS configuration and accessibility.
- Execute a dig command for app.nimbl.ad to verify that the subdomain correctly resolves to your App Service’s IP address or <appname>.azurewebsites.net.
- Use curl -i to test http://app.nimbl.ad/ and confirm that index.html returns a 200 status code.
- Use Azure CLI for Detailed Errors:
- Run:
az webapp config ssl create --resource-group <YourResourceGroup> --name <YourAppName> --hostname app.nimbl.ad - Share the error output if it fails.
- Run:
- Enable Logging:
- Go to Monitoring > App Service logs, enable Application Logging (Filesystem), set to Verbose.
- Retry certificate creation and check logs via Log stream or Kudu (https://<yourapp>.scm.azurewebsites.net/) for token placement errors.
References:
https://learn.microsoft.com/en-us/azure/azure-monitor/agents/diagnostics-extension-overview
After success, remove index.html, re-enable HTTPS Only, and restore Cloudflare proxy.
- Run Azure Diagnostics:
-
Dan Piccot • 0 Reputation points
2025-10-22T17:04:47.5233333+00:00 The website is only a single index.html file now to prevent any SPA redirects from messing things up, so there isn't a web.config file at all now and no blazor redirects in place.
I was able to create the dummy file and got a 200 OK using
curl -i http://app.nimbl.ad/.well-known/pki-validation/fileauth.txt
Http-Only is confirmed off.
Lastly, running the CLI command results in a similar error to the one in the UI
Bad Request({"Code":"BadRequest","Message":"Pending managed certificate failed: Website not available for updating validation token. Refer to the documentations for more info: https://go.microsoft.com/fwlink/?linkid=2158627.","Target":null,"Details":[{"Message":"Pending managed certificate failed: Website not available for updating validation token. Refer to the documentations for more info: https://go.microsoft.com/fwlink/?linkid=2158627."},{"Code":"BadRequest"},{"ErrorEntity":{"Code":"BadRequest","Message":"Pending managed certificate failed: Website not available for updating validation token. Refer to the documentations for more info: https://go.microsoft.com/fwlink/?linkid=2158627."}}],"Innererror":null})
Below is also the logs that appear in the Log stream while this process was running.
2025-10-22T17:03:33 Welcome, you are now connected to log-streaming service. The default timeout is 2 hours. Change the timeout with the App Setting SCM_LOGSTREAM_TIMEOUT (in seconds).
2025-10-22 17:02:55 ~17-SOULVERE GET /api/commandstream/ping shell=CMD&_=1761150773635&X-ARR-LOG-ID=c44052fe-0c29-4aca-9084-1812977440f6 443 - 104.139.104.186 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/141.0.0.0+Safari/537.36 __RequestVerificationToken=f74cd00f-8751-4967-9632-bf679dcd13ba;+ARRAffinity=8a7606b94422330118dfa10eed4ff963181e1cfdefa42007cd858e855f2b2daa;+ARRAffinitySameSite=8a7606b94422330118dfa10eed4ff963181e1cfdefa42007cd858e855f2b2daa https://7-soulvere.scm.azurewebsites.net/DebugConsole 7-soulvere.scm.azurewebsites.net 200 0 0 584 1861 15
2025-10-22 17:02:33 7-SOULVERE GET / X-ARR-LOG-ID=62f7c18b-cfaf-492b-997a-f3f5ef6304f2 80 - 40.71.13.64 - - - app.nimbl.ad 200 0 0 3738 535 3
2025-10-22 17:02:37 ~17-SOULVERE POST /daas/sessions/list api-version=2015-08-01&X-ARR-LOG-ID=580e64ee-21e9-4474-b7cb-093f6e87d6a9 443 - 40.71.13.64 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/141.0.0.0+Safari/537.36 - https://management.azure.com/subscriptions/b699423e-d7ad-4f5f-a3a6-f09e86f68d6e/resourceGroups/devops/providers/Microsoft.Web/sites/7-soulvere/extensions/daas/sessions/list?api-version=2015-08-01 7-soulvere.scm.azurewebsites.net 200 0 0 685 4127 26
2025-10-22 17:03:04 7-SOULVERE GET / X-ARR-LOG-ID=d1540008-c626-4c5e-bfef-8f1b173fe04e 80 - 40.71.13.64 - - - app.nimbl.ad 200 0 0 3738 533 2
2025-10-22T17:04:11 PID[32080] Information Request, Method=POST, Url=https://7-soulvere.scm.azurewebsites.net/daas/sessions/list?api-version=2015-08-01, Message='https://7-soulvere.scm.azurewebsites.net/daas/sessions/list?api-version=2015-08-01'
2025-10-22T17:04:11 PID[32080] Information Message='Session', Operation=DefaultHttpControllerSelector.SelectController
2025-10-22T17:04:11 PID[32080] Information Message='DiagnosticsExtension.Controllers.SessionController', Operation=DefaultHttpControllerActivator.Create
2025-10-22T17:04:11 PID[32080] Information Message='DiagnosticsExtension.Controllers.SessionController', Operation=HttpControllerDescriptor.CreateController
2025-10-22T17:04:11 PID[32080] Information Message='Selected action 'ListSessions()'', Operation=ApiControllerActionSelector.SelectAction
2025-10-22T17:04:11 PID[32080] Information Operation=HttpActionBinding.ExecuteBindingAsync
2025-10-22T17:04:11 PID[32080] Information Message='Action returned 'System.Web.Http.Results.OkNegotiatedContentResult
1[System.Collections.Generic.IEnumerable1[DaaS.Sessions.Session]]'', Operation=ReflectedHttpActionDescriptor.ExecuteAsync2025-10-22T17:04:11 PID[32080] Information Message='Selected formatter='JsonMediaTypeFormatter', content-type='application/json; charset=utf-8'', Operation=DefaultContentNegotiator.Negotiate
2025-10-22T17:04:11 PID[32080] Information Operation=ApiControllerActionInvoker.InvokeActionAsync, Status=200 (OK)
2025-10-22T17:04:11 PID[32080] Information Operation=SessionController.ExecuteAsync, Status=200 (OK)
2025-10-22T17:04:11 PID[32080] Information Response, Status=200 (OK), Method=POST, Url=https://7-soulvere.scm.azurewebsites.net/daas/sessions/list?api-version=2015-08-01, Message='Content-type='application/json; charset=utf-8', content-length=unknown'
2025-10-22T17:04:11 PID[32080] Information Operation=JsonMediaTypeFormatter.WriteToStreamAsync
2025-10-22T17:04:11 PID[32080] Information Operation=SessionController.Dispose
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-22T18:15:19.98+00:00 Hi @Dan Piccot
Thank you for the detailed update and for confirming the steps taken. It’s good to hear that your dummy validation file at http://app.nimbl.ad/.well-known/pki-validation/fileauth.txt returns a 200 OK and that HTTPS Only is disabled with no SPA redirects or web.config issues.
However, the ongoing error ("Pending managed certificate failed: Website not available for updating validation token") and the lack of specific validation errors in your logs suggest that Azure still cannot place or access the token during validation.
For further troubleshooting, kindly follow these steps:
To continue troubleshooting, please follow these steps:
- Please review the file system to verify the placement of tokens.
- Go to Kudu at
https://7-soulvere.scm.azurewebsites.net/and navigate to site/wwwroot/.well-known/pki-validation/. - Try creating the certificate again from the Azure Portal or CLI, then immediately verify if the token file appears. If it does not, Azure is not writing the token.
- If the token file appears but validation fails, download it and share its contents to verify the format.
- Review App Service Configuration:
- In the Azure Portal, under Networking > Inbound traffic, check that Public network access is enabled and there are no restrictions or IP filters blocking DigiCert’s IPs (e.g., 216.168.249.9, 216.168.240.4).
- Confirm your app’s pricing tier is Basic or higher, as managed certificates are not supported on free or shared tiers.
- In Custom domains, make sure your domain is verified (green checkmark). If not, remove and re-add the domain, ensuring DNS is set up correctly.
- Please verify the accessibility of the test validation path.
- Since your dummy file is accessible, temporarily rename it (e.g., fileauth_temp.txt) to prevent conflicts.
- Try creating the certificate again and use curl -i to check fileauth.txt within 5-15 minutes. If you get a 404 or redirect, it suggests a server-side issue.
- If there are redirects, review your Azure configuration or middleware settings.
- Please provide more detailed logging information.
- Go to Monitoring > App Service logs, turn on Application Logging (Filesystem) at Verbose level and enable Detailed Errors.
- Then rerun the CLI command:
az webapp config ssl create --resource-group <YourResourceGroup> --name 7-soulvere --hostname app.nimbl.ad - Monitor Log stream for any token or validation-related errors; share logs as needed.
- Manual Validation Trigger:
- In the Azure Portal, try manually creating the managed certificate by going to TLS/SSL settings > Private Key Certificates > Create App Service Managed Certificate.
- Next, check if fileauth.txt appears, and wait 15-20 minutes for the validation process to finish.
Once validation is successful, you can restore your previous app configuration and Cloudflare proxy settings. If you have any new logs or command outputs, please share them for further support.
If still issue not fixed, we have reached out to you in Private messages for additional details, could you please look into it and share us the details?
References:
https://learn.microsoft.com/en-us/azure/azure-monitor/agents/diagnostics-extension-overview
-
Dan Piccot • 0 Reputation points
2025-10-22T18:41:17.2233333+00:00 1)Check the File System for Token Placement:
- Renamed and checked the folder during creation, no file was ever created. Settings also checked and confirmed correct like you mentioned.
-
- Logging Detail
No validation, or otherwise errors appearing in the logs as I ran this.
3)Manual Validation Trigger
- Went into the Certificates section and clicked add certificate (I couldn't find a TLS/SSL settings section). This resulted in the same error and the fileauth.txt file was never created.
-
- Renamed and checked the folder during creation, no file was ever created. Settings also checked and confirmed correct like you mentioned.
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-23T10:00:34.0533333+00:00 Hi @Dan Piccot
After a detailed investigation, we found that the "Pending managed certificate failed: Website not available for updating validation token" error for app.nimbl.ad on 7-soulvere occurs because Azure misinterprets .ad as .a. Additionally, missing DNS records prevent domain verification, which halts the certificate process. Your HTTP access and Cloudflare DNS Only configuration are correct.
Here’s how to fix it:
Update DNS in Cloudflare:
- For app.nimbl.ad:
- Configure an A record or CNAME that points to your Azure application.
- Add the necessary TXT record for domain verification, using the value provided in your Azure portal.
- Include a CAA record to permit certificate issuance.
Add App Setting:
- In Azure portal > Configuration > Application settings for 7-soulvere, add:
- Name: WEBSITE_LOAD_CERTIFICATES
- Value: *
- Please save the changes and proceed to restart the application.
Re-verify Domain:
Remove and re-add app.nimbl.ad under Custom domains.
Confirm green checkmark.
Retry Certificate Creation:
Go to TLS/SSL settings and create the App Service Managed Certificate.
Report TLD Issue:
Azure is misparsing your domain extension. Please report via Azure User Voice with your app name and domain.
Check Token Placement:
- Use Kudu to rename dummy fileauth.txt and retry certificate issuance.
- Verify token availability via curl command.
We have reached out to you via private message and shared a complete set of troubleshooting steps to help resolve the issue.”
References:
https://learn.microsoft.com/en-us/azure/azure-monitor/agents/diagnostics-extension-overview
-
Praneeth Maddali • 12,670 Reputation points • Microsoft External Staff • Moderator
2025-10-29T10:50:04.8033333+00:00 Hi @Dan Piccot
From the following suggestions provide in Private ChatAs per our investigation, it appears that the issue has been resolved. We are seeing that the certificate
app.nimbl.ad-7-Soulverewas updated successfully. Could you please check and confirm from your end?We have reached out to you in Private messages, could you please look into it and confirm
-
Shree Hima Bindu Maganti • 7,590 Reputation points • Microsoft External Staff • Moderator
2025-11-04T06:36:12.71+00:00 Hi @Dan Piccot
Apology for your inconveniences.
The error “Pending managed certificate failed due to Website not available for updating validation token” occurs because Azure App Service cannot reach the validation token required to issue the managed SSL certificate. When Azure validates your domain, it places a temporary token on your web app and attempts to access it via HTTP. If this access is blocked due to Cloudflare’s proxy (orange cloud), firewall restrictions, or leftover pending certificates from a previous failed attempt the certificate issuance fails. To resolve this, temporarily set your Cloudflare DNS records (A or CNAME) for the domain/subdomain to DNS only (gray cloud) so Azure can access the validation token directly. Next, delete any pending certificates in the App Service portal under TLS/SSL settings Private Key Certificates, and restart the app. Ensure your domain’s CAA records allow DigiCert (or Azure’s provider) to issue certificates. After these checks, retry creating the App Service Managed Certificate. Once successfully issued, you can re-enable the Cloudflare proxy. If the issue persists, as a fallback, you can use a third-party SSL certificate (e.g., DigiCert or Let’s Encrypt) and upload it manually to App Service.App Service Managed Certificates – Microsoft Learn
https://learn.microsoft.com/en-us/answers/questions/5536797/timeout-creating-new-app-service-managed-certifica?utm_source=chatgpt.com
Let me know if you have any further assistances needed.
Sign in to comment