Signing is still failing after reinstatement.

dchapman 80 Reputation points
2026-06-10T16:40:11.04+00:00

Our signing identity has been reinstated but signing operations are failing on both certificate profiles. We have tested both profiles from GitHub Actions and both return status: Failed with signature: null and signingCertificate: null.

Operation IDs:

  • Teldio (production): PII
  • TeldioTest (staging): PII

Both profiles show Active status in the portal with valid certificates. Authentication is succeeding (operation IDs are being returned), but the signing operations fail server-side. This appears to be an incomplete re-provisioning of the account after the suspension was lifted.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)


Answer accepted by question author

AI answer

2026-06-10T16:40:30.0766667+00:00

The described behavior matches a post-suspension state where identity validation or certificate profile linkage is not fully restored, even though profiles show Active and certificates appear valid.

Based on the documented behavior of Artifact Signing after identity validation or account issues, the following checks and remediation steps apply:

  1. Verify identity validation status
    • In the Artifact Signing account, open Identity Validation and confirm the status is Completed for the identity used by both Teldio and TeldioTest profiles.
    • If the identity validation is expired or not completed, signing operations associated with those profiles will stop, even if profiles appear active.
  2. If identity validation was renewed or recreated, rebind certificate profiles
    • After identity validation issues (including expiration or re-creation), certificate renewal and signing can stop until profiles are re-associated.
    • From the Artifact Signing account:
      1. Go to Certificate Profiles.
      2. Identify the profiles associated with the affected identity validation.
      3. Delete the existing certificate profiles associated with the previously expired/affected identity validation.
      4. Recreate new certificate profiles with the same names (Teldio, TeldioTest).
      5. When recreating, explicitly select the correct Identity Validation from the dropdown.
    • Once the new certificate profiles are created successfully and tied to a Completed identity validation, signing should resume without changes to existing metadata.json or pipeline configuration.
  3. Confirm identity validation is not expired again
    • Ensure the identity validation has not re-expired. If it has, create a new identity validation and repeat the profile re-creation steps above.

If, after confirming a Completed identity validation and recreating/rebinding the certificate profiles, signing still fails with signature: null and signingCertificate: null, raise a support case with Azure Support including the operation IDs and confirmation that the identity validation and certificate profiles were re-created as per the documented process.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.