Try this:
On the RBAC Key Vault, assign Key Vault Administrator
to Microsoft.Azure.CertificateRegistration
service principal.
After that, you can link your Certificate to this Key Vault and see what happens.
See reference.
Let me know how that works
You can mark it 'Accept Answer' and 'Upvote' if this helped you
Regards,
Abiola