Unfortunately, it only works if you have primary domain cert from Digicert.
Azure app certs are GoDaddy and managed cert now is Digicert. It is confusion for deployment and implementation when services are featured as Azure product and behind the scene it is not actually AZ services. I tried using it to create and failed as I have GoDaddy cert from KV which does not allow managed domain implemented by Digicert

