A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
For a Public Trust certificate profile, the selected Verified CN and O must come from a completed Public identity validation that aligns with the Public Trust model. A Private Trust identity validation can populate Private Trust profiles, but it cannot be used for a Public Trust profile.
Checks to perform:
- In the Azure portal, open the Artifact Signing account.
- Go to Objects > Identity validations.
- Open the validation that shows Completed and confirm it was created as:
- Organization > New Identity > Public
- not Private
- If the completed validation is Private, create a new Public identity validation. Public identity validation is the one that applies to these certificate profile types: Public Trust, Public Trust Test, and VBS Enclave.
- After the Public identity validation finishes successfully, go to Objects > Certificate profiles > Create > Public Trust and select that completed validation in Verified CN and O.
Important behavior:
- A prerequisite for creating any certificate profile is to have at least one completed identity validation request.
- Identity validations and certificate profiles align with either Public Trust or Private Trust. A Public Trust identity validation is used only for certificate profiles that are used for the Public Trust model.
- Identity validation can be completed only in the Azure portal.
If the validation is already a completed Public identity validation and the portal still says "Please complete the Identity Validation", the available context does not provide a documented self-service fix for that portal mismatch.
References: