A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
For HTTP 403 from Artifact Signing, the supported checks are these:
- Verify the signing identity has Artifact Signing Certificate Profile Signer.
- Verify the Artifact Signing account name and certificate profile name in
metadata.jsonexactly match the Azure resource names. - Verify the identity validation status is Completed.
- Verify the certificate profile status is Active.
- Verify the dlib and dlib path.
- Verify the .NET version, dlib version, and Windows SDK version are compatible.
- Install the Microsoft Visual C++ Redistributable (x64).
- Verify the machine can reach the Artifact Signing endpoint; if needed, try the same signing operation from a different VM or computer because 403 can indicate a network issue.
- For authentication-chain issues, exclude unwanted credentials in the manifest/JSON. A documented mitigation for Azure authentication and a moderator-recommended fix for 403 cases is to add
ExcludeCredentialsentries so the client does not pick the wrong cached identity.
Since the same 403 occurs with both SignTool+dlib and Invoke-ArtifactSigning, and the failure happens at Submitting digest for signing..., that narrows the issue to service authorization, identity selection, endpoint access, or profile/account state rather than the EXE itself.
A focused next pass is:
- In the signing JSON, add
ExcludeCredentialsto eliminate cached or unintended identities, especially if multiple Azure sign-in methods exist on the machine. - Reconfirm the exact Artifact Signing account name is the resource name, not a user name or app registration name.
- Reconfirm the signing identity has the Artifact Signing Certificate Profile Signer role on the Artifact Signing account.
- Test from a different machine or VM to rule out local network or endpoint-access issues.
- If using service principal with certificate-based authentication, verify the required environment variables.
If the issue is specifically a wrong credential being selected, excluding credentials such as EnvironmentCredential, ManagedIdentityCredential, SharedTokenCacheCredential, VisualStudioCredential, VisualStudioCodeCredential, AzurePowerShellCredential, and AzureDeveloperCliCredential has resolved 403 cases.
Also verify the local tooling prerequisites because silent or misleading failures can occur when dependencies are missing:
- Use the matching x64 SignTool with the corresponding x64 Azure.CodeSigning.Dlib.dll.
- Use the recommended Windows SDK version.
- Ensure x64 .NET 8 or later is installed.
- Ensure the VC++ x64 redistributable is installed.
References:
- Artifact Signing FAQ
- Set up signing integrations to use Artifact Signing
- CLI Documentation and Usage
- Unable to get artifact signing to work. - Microsoft Q&A Hi, I need help getting the signing to work.
- SignTool gives Error information: "Error: SignerSign() failed." (-2147467259/0x80004005) - Microsoft Q&A
- How to debug 403 Forbidden using SignTool w/ Trusted Signing? - Microsoft Q&A