The primary AD FS token-signing certificate is self-signed. Your federation servers and claims provider partners need to ...