I have setup two AD DS forest which are both setup for domain join with Azure Active Directory using AAD Connect latest version.
I have a federated scenario using ADFS 2016 and everything seems to work fine. I now also activated Hello for Business with Key trust scenario, and also this works without detecting any problems.
Because I have ADFS, ADCS and also have services depending on smartcard authentication (certificate auth) I would like to switch Hello for Business to certificate trust instead of Key trust.
So I started checking if everythings is in order to get this working. I noticed the following AadCloudAPPlugin event errors, is there anybody who can explain what general problem I am having here. Or how to fix this.
1081
OAuth response error: invalid_request
Error description: AADSTS500032: Cannot find signing certificate/private key to issue a certificate.
Trace ID: 3d98d0ff-a9d3-449e-ba8c-4e6add0b2900
Correlation ID: 2d4fd0b9-bc54-4d3a-8704-f3a137f19529
Timestamp: 2019-01-13 08:11:18Z
CorrelationID: 2d4fd0b9-bc54-4d3a-8704-f3a137f19529
1131
Update P2P device certificate failure. Status: 0xC00000D0 Correlation ID: 2D4FD0B9-BC54-4D3A-8704-F3A137F19529
1165
Logon failure. Status: 0xC00000D0 Correlation ID: 2D4FD0B9-BC54-4D3A-8704-F3A137F19529
1025
Http request status: 400. Method: POST Endpoint Uri: https://<FQDN adfs>/adfs/oauth2/token/ Correlation ID: 57BB9433-BE34-4EAF-B7BA-E9503D5C0FF9
1081
OAuth response error: invalid_grant
Error description: MSIS9682: Received invalid OAuth JWT Bearer request. The certificate used to sign JWT Bearer request is not from a registered device with a Transport key.
CorrelationID:
1118
Enterprise STS Logon failure. Status: 0xC000006D Correlation ID: 57BB9433-BE34-4EAF-B7BA-E9503D5C0FF9
1025
Http request status: 400. Method: POST Endpoint Uri: https://login.microsoftonline.com/ff65dbab-37bf-42ae-939b-d08ed05f1799/oauth2/token Correlation ID: B9B93936-03A2-485C-8925-95F31075F173
Mike Couwenbergh IT Infrastructuur Architect