The primary AD FS token-decrypting certificate is self-signed. Your federation servers and claims provider partners need ...