The primary AD FS token-decrypting certificate does not have a private key on one or more AD FS servers. AD FS cannot decrypt ...