Public Trust certificate profile fails to issue (Failed, blank subject), cannot create or delete

Jerry 0 Reputation points
2026-06-16T07:21:29.65+00:00

Hi, hoping someone from the Trusted Signing team can help, since this looks like a backend issue I can't fix myself.

On my Artifact Signing account "heliosoftsigning" (subscription 2908bf7e-9847-4058-aa23-36cda7910ada, East US), every Public Trust certificate profile I create ends up in Failed status with a blank Subject... no certificate ever gets issued. My org identity validation (HELIOSOFT LTD, UK) is Completed and valid to 2028 and i got the approval yesterday morning.

I've tried two profiles (subnetlens and subnetlens1) and both fail identically. I also deleted an old Failed identity validation in case it was interfering... no change. And I can't delete the failed profiles either: both the portal and "az trustedsigning certificate-profile delete" return "UnknownError / Some error occurred".

Correlation IDs — create: 0b872b0f-6c0d-4991-b261-bac8a2e5a6f3, delete: 1e90aa57-e1e5-4559-8da7-f3580fe77dbb

Does anyone have a solution to this and Could someone from the microsoft team look into why issuance keeps failing on this account, and help clear the two stuck profiles? Thanks!

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-06-16T07:21:45.6633333+00:00

    This behavior can’t be fixed from the client side. The account is in a state that requires Microsoft support to intervene on the backend.

    For Public Trust certificate issues where:

    • Certificate profiles stay in Failed with a blank subject and no certificate is issued, and
    • Deletion of the failed profiles in both the Azure portal and az trustedsigning certificate-profile delete returns generic errors,

    the supported path is:

    1. Do not keep retrying deletes via CLI/portal for the stuck profiles; the errors indicate a backend problem, not a parameter issue.
    2. Open a support case with Microsoft for Artifact Signing and provide:
      • Subscription ID and Artifact Signing account name.
      • Certificate profile names.
      • Correlation IDs for both the failed creation and failed deletion attempts.
    3. If misuse or abuse is suspected (not indicated here), follow the misuse/abuse contact path; otherwise, standard Azure support is appropriate.

    Once Microsoft clears or fixes the stuck profiles and any backend validation/issuance issue on the account, new Public Trust certificate profiles can be created and should issue correctly.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.