Azure App Service自定义子域名SSL证书验证步骤4失败求助
First, let’s recap what you’ve already nailed down: you’ve mapped your custom subdomain via CNAME to your Azure App Service, successfully assigned it in the portal, and can access the default page using that subdomain. Nice work getting that far!
Now, here are the most common fixes to get past the stuck "Verify domain ownership" step when using the App Service validation method:
Double-check the domain’s assigned status
Even though you see the domain listed in "HOSTNAMES ASSIGNED TO SITE", head to your App Service’s Custom Domains blade and confirm the domain shows a green checkmark under "Status". Sometimes DNS propagation looks good, but the portal’s internal status takes a few minutes to catch up—wait 5-10 minutes and refresh if needed.Confirm your App Service plan tier
The App Service validation method only works with Basic, Standard, Premium, or Isolated plans. If you’re on Free or Shared tier, this method won’t function at all. You’ll need to either upgrade your plan or switch to a different validation method (like TXT record verification) to proceed.Validate the hidden auto-created CNAME record
When you choose App Service validation, Azure automatically creates a hiddenasuid.<your-subdomain>CNAME record pointing to an Azure-owned domain. You can verify this exists using a DNS lookup tool in your terminal:
Runnslookup asuid.your-subdomain.your-domain.com
If it doesn’t resolve, delete and reassign the custom domain in the Azure portal to trigger the record creation again.Clear conflicting DNS records
If you’ve attempted validation before, there might be an oldasuid.<your-subdomain>TXT record lingering in your DNS settings. This can conflict with the auto-created CNAME. Delete any oldasuidrecords for your subdomain and retry the validation step.Restart your App Service
A simple restart can refresh the domain association and validation state. Go to your App Service’s overview blade, click Restart, wait for it to fully reboot, then try verifying again.Fall back to manual TXT record validation
If all else fails, switch to the TXT record option in the validation step. Create the specified TXT record in your DNS provider, wait 10-30 minutes for propagation, then click Verify. This is a reliable workaround when the App Service method hits snags.
内容的提问来源于stack exchange,提问作者Sarvesh Gupta

