The primary AD FS token-signing certificate does not have a private key. AD FS cannot issue signed tokens. Your users may ...