The LSAuthenticationObject method LogonClient was called with certificate credentials, but only Active Directory Lightweight ...

The LSAuthenticationObject method LogonClient was called with certificate credentials, but only Active Directory Lightweight Directory Services (AD LDS) account stores are configured at the Federation Service. AD LDS account stores do not support certificate credentials. 

User Action 
If this Federation Service is intended to service certificate authentication logons, configure the Active Directory Domain Services account store. 

If this Federation Service is not intended to service certificate authentication logons, consider replacing ls/auth/sslclient/clientlogon.aspx with a static page that indicates that certificate authentication is not supported.