The Primary AD FS Token Signing certificate does not have a private key. AD FS cannot issue signed tokens. User authentication ...