Certificate creation was rejected by CA for canonical name

William 1 Reputation point
2022-10-27T08:09:29.15+00:00

I'm trying to get a managed certificate for my custom domain (a subdomain on another domain), but it keeps failing.

  1. Add a custom domain XX with record type being CNAME.
  2. Domain provider: "All other services", TLS certificate: Add certificate later
  3. In "Custom domains (preview)", click "Add binding". Set TLS/SSL type to SNI SSL, Source to "Create App Service Managed Certificate".
  4. Validate --> Wait until valid
  5. Add. Wait until the certificate creation process fails.

Failed to create App Service Managed Certificate for

Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
8,984 questions
{count} votes

2 answers

Sort by: Most helpful
  1. SnehaAgrawal-MSFT 22,706 Reputation points Moderator
    2022-10-31T12:00:11.917+00:00

    @William Thanks for reply! Appreciate for sharing the resolution that waiting and adding a binding again works for you.
    This will help other community members as a guidance when facing similar issue.

    0 comments No comments

  2. Mauricio Vieira 0 Reputation points
    2023-09-05T12:28:43.4466667+00:00

    Hi Folks.

    I'm facing the same issue as reported here. I've waited so many days, and even reinstalling the webapp and with adding a new domain, i get the same error

    Error adding managed certificate: Pending managed certificate failed: Certificate creation was rejected by CA for canonical name www.domain.com: A CNAME record was found but does not point to a whitelisted domain. If retrying does not help, please contact support for assistance.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.