Issuer of token is NOT a trusted issuer

hi,
am facing an issue in SharePoint portal which connects to ADFS sever.
I have verified Provider name, Certificate details in SharePoint and all ADFS configuration settings in ADFS sever,
found no configuration issue.
 if you know any resolution steps , then pls let me know . Below is error message we are getting when we access the SharePoint
site

Hi Benjamin,
According to your description, my understanding is that you got an error when you connected ADFS to SharePoint 2010.
1.Verify the appropriate certificate chain is present on the SharePoint server in both the trusted root authorities as well as in the SharePoint folder within the Certificate MMC snap-in.
2.Verify that you actually used the right certificate when specifying the certificate path when building the System.Security.Cryptography.X509Certificates.X509Certificate2 object to pass into your SPTrustedIdentityTokenIssuer.
Here are some similar post your reference:
http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-adfs-securitytokenexception-the-issuer-of-the-token-is-not-a-trusted-issuer/
http://blogs.technet.com/b/speschka/archive/2012/05/17/the-issuer-of-a-token-is-not-a-trusted-issuer-craziness-with-saml-claims-in-sharepoint-2010.aspx
http://social.technet.microsoft.com/Forums/sharepoint/en-US/bc42ffc3-02b6-4d4d-bd47-d4cbeccc9df2/sharepoint-2010-and-adfs-20-cert-problem
http://blogs.msdn.com/b/ekraus/archive/2010/03/22/sharepoint-2010-claims-based-auth-with-adfs-v2.aspx
I hope this helps.
Thanks,
Wendy
Wendy Li
TechNet Community Support

Similar Messages

  • Multi-issue app with subscription not show any issue of the magazine

    Hi all,
    I recently migrated my magazine from multi-issue app to multi-issue with itunes subscription app. I want to publish my magazine into the newsstand with free subscription.
    If I install on my ipad the .ipa I see all the issue published in the last year and a half. I can subscribe the free subscription and all working properly.
    When Apple store approve the app they told me that no magazine appears in my app (and the screenshoot they attached me confirm this).
    I can't understand what could have happened.
    On the development ipad was previously installed the normal version of the app (with no subscription). Is this a problem?

    I agree with poorxperiaplay here.  The problem is directly related to all Google services not just Gtalk, thats why Gmail doesn't sync right, nor does the calendar, nor does it work right when you pick out an app on the Google Play web site on your PC and try to install from there.  It never live syncs with the server. 
    You can't just take out features like that because you broke them and then say sorry.  People rely on the Google services, its why we bought an Android Phone!  Not only that, ALL other versions of the Xperia Play, R800i, R800a, R800at, all run 2.3.4 official from Sony successfully.  Verizon modifies it for roll out to their phones, to add their software, which means your product team broke it, and they aren't spending the time to fix it. 
    And yes the facebook application does not sync properly or even work properly on 3G either.  The sync issue has been a problem from day 1.  The web site on the phone works fine. 
    These are major issues that are fundamental to all R800x phones.  This needs to be fixed, immediately.

  • Custom STS trust issue with SharePoint

    Hello,
    This is my first time creating a custom STS and I've been running into some problems with it. I'm using VS 2012 on SharePoint 2013.
    I have created a custom STS that I’d like to use to authenticate users to SharePoint. I created simple stand along web-application that I was using to test logging in with the STS and it seemed to work fine. The environment I’m using is as below:
    A single App/WFE dev server. SQL is separate.
    A custom STS site that I deployed to the server. I gave it the URL
    http://customsts.dev I added an entry to the local hosts file for it.
    I used PluralSight’s SelfCert 3<sup>rd</sup> party tool to create a new certificate. I added that cert to the Trusted Root Certification Authorities and also to the SharePoint Certificates stores on the server via the MMC.
    I use the certificate Key for signing the claim in the STS.
    I created a sample stand-alone Non-SharePoint web site to log in using the STS and it seems to work.
    dfd- Next,
    I created a SharePoint web-application and called it http://servername:1111.
    Next I ran the following powershell set up a new trusted identity provider in SharePoint:
    $cert = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2("e:\pla\customsts.dev.cer")
    $map1 = New-SPClaimTypeMapping "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress" -IncomingClaimTypeDisplayName "EmailAddress" –SameAsIncoming
    $realm = http://servername:1111/_trust/
    $signinurl = https://customsts.dev/Account/Login
    New-SPTrustedRootAuthority -Name “customsts.dev” -Certificate $cert
    New-SPTrustedIdentityTokenIssuer -Name "customsts.dev" -Description "Passport STS" -Realm $realm -ImportTrustCertificate $cert -ClaimsMappings $map1 -SignInUrl $signinurl -IdentifierClaim $map1.InputClaimType
    I set the customsts.dev as the Trusted Identity Provider for the web-app at 1111.
    I noticed that when I try to log into the web-application, I get the option to pick the authentication, and then get redirected to the login page of the customsts.dev STS. When I attempt to log in, I get routed back to SharePoint and see this error in
    the ULS logs:
    Application error when access /, Error=The issuer of the token is not a trusted issuer. 
     at Microsoft.SharePoint.IdentityModel.SPLocalIssuerNameRegistry.GetIssuerName(SecurityToken securityToken)   
     at Microsoft.IdentityModel.Tokens.Saml11.Saml11SecurityTokenHandler.CreateClaims(SamlSecurityToken samlSecurityToken)   
     at Microsoft.IdentityModel.Tokens.Saml11.Saml11SecurityTokenHandler.ValidateToken(SecurityToken token)   
     at Microsoft.IdentityModel.Tokens.SecurityTokenHandlerCollection.ValidateToken(SecurityToken token)   
     at Microsoft.IdentityModel.Web.TokenReceiver.AuthenticateToken(SecurityToken token, Boolean ensureBearerToken, String endpointUri)   
     at Microsoft.IdentityModel.Web.WSFederationAuthenticationModule.SignInWithResponseMessage(HttpRequest request)   
     at Microsoft.IdentityModel.Web.WSFederationAuthenticationModule.OnAuthenticateRequest(Object sender, EventArgs args)   
    I have tried searching for solutions to this and seem to have exhausted all the options. Does anyone have any experience with this? I'm wondering if there's anything that I'm doing incorrectly in setting up the STS. Any help in this regard would be very
    appreciated.
    Thanks,
    Sudharsan.

    Hi,
    the certificate you used to create trust is a self signed cert ???
    if yes try this with a domain certificate.
    Whenever you see a reply and if you think is helpful,Vote As Helpful! And whenever you see a reply being an answer to the question of the thread, click Mark As Answer

  • Skype/Windows Live ID Issues & password token not ...

    I'm having a few issues, I cannot seem to login into skype with my previous username, alternatively, this problem started when I linked my hotmail.com account to my current skype account.
    I've been having a huge issue with this, although when I tell it to sign me in with my live id (while I'm logged into MSN), it will allow me to, but I can't do it on the actual skype program. More to the point, I want my username to stay the way it was when I joined Skype back 6 years ago.
    Furthermore, I cannot reset my password via the Skype based forget password routine because every time I try it says the token was not recognized. I'm not sure where I should begin but I would like to restore my service the way it was before.
    Who should I talk to?
    I would like to restore my service back to the way it was.

    I also have the exact issue and support does not have a resolution.  It might be time for the Skype team to talk to the Messenger team and figure out how to log in a Microsoft account user correctly like they did in Messenger without issue.

  • Re-Imaging and Security Related Trust Issues

    Hello,
    Yesterday, I asked the question about how to fix having trust issues all the time when re-imaging computers in a school environment. I am using Windows Server 2008R2 and a Windows 7 Image created in FOG image program. The machines we use are HP5100 Desktop
    machines.  I didn't feel that I properly explained in the first post how we re-image the machines. I am hoping this will give you a better idea of what we are doing, and you can help me figure this issue out. Thank you in advance.
    Step 1: Bring Windows 7 Image down to an HP5100 Desktop, update plugins and send image update back up in Fog
    Step 2: Delete all machines out of the active directory for specified labs.
    Step 3: Re-image school labs of 30 machines each
    Step 4: Rename each machine with unique id, example : BJSHS203S01DW7 (name of school, lab #, Student #, and OS)
    Step 5: Join the domain
    Step 6: Make necessary adjustments, and use deep freeze to freeze machines up
    Those are the steps we use when re-imaging, and so far for the past two years we have sporadic issues with two labs in particular with receiving trust-relationship message, and also sometimes get a message that says there are no servers available. When this
    happens, then I need to go to the machine unfreeze it, unjoin the domain, delete the name from the active directory, and then rejoin the domain. Sometimes this works but more often than not it doesn't work so well, and then I have to go through the whole process
    again. We do not use sysprep on our machines.
    So my question is this : What am I doing wrong? Is there anything you can recommend to fix this problem so that I don't have to continue to fix the machines and waste time?
    Thank you in advance, I appreciate your help!!
    Angie

    Deep Freeze may be causing your problems.  Have you read this article from Deep Freeze makers about trust relationship issues?
    http://support.faronics.com/Knowledgebase/Article/View/365/8/computers-running-deep-freeze-loose-connection-to-or-fall-off-the-domain-with-an-error-that-the-trust-relationship-between-the-domain-controller-and-the-workstation-has-failed

  • Custom Font issue - Works in Win7 not in XP

    I followed Rakesh's guide over here: [http://blogs.sun.com/rakeshmenonp/entry/javafx_custom_fonts]
    My file/folder structure is identical to his guide's.
    I've tested to see if the actual fonts.mf file was actually working on my Win7 box, where I actually changed the font name to gibberish (which forces the font to default to a system standard font) and back again to the font name I specified in my fonts.mf file, which works fine.
    However, when I launch my application under XP, the font does not seem to register. Of course, I made sure to delete any certs/cache.

    For the record, the console did not report any missing fonts or anything similar.
    It finally started working, but I did something a little different this time, in terms of clearing the cache.
    I usually just deleted the 6.0 directory in cache:
    ...username\Application Data\Sun\Java\Deployment\cache and delete the 6.0 directory. Since doing it this way, I have not encountered an issue when I want to redeploy my application on the same machine.
    I would also sometimes delete the trusted.certs file for good measure. It's probably not necessary, but it's easy enough to do.
    This time around, I deleted the 6.0 directory in the \SystemCache directory. I actually did not realize that this needed to be done. The fact that I did not have to do this on my Win7 machine makes me wonder why I had to do it on the XP machine. But either way, it's working.
    Maybe someone would like to comment on Java's caching system and if there are any differences between Win7 and XP?

  • Single Label Domain - Corss Forest trust issue!

    Hello There
    We have a single label root domain ex: "abc" trying to establish the external trust with the other forest's root domain which is FQDN ex: xyz.com. The trust seems to be working fine from abc to xyz.com however the trust from xyz.com to abc is an
    issue.
    We are not able to resolve/ping domain abc from xyz.com DC. We are able to ping DCs in abc from xyz.com.
    On xyz.com DNS forwarder are pointing to abc DNS server and WINS has been configured to route to abc WINS. Everytime when I ping abc from xyz.com DC its pointing to some unknown IP.
    on the xyz.com DC tried setting up the registry key AllowSingleLabelDnsDomain, updated the LMHOSTS and host file with abc domain but still unable to resolve the single label domain. We could not suspect that its an issue with the network as we are able to
    ping abc domain DCs from xyz.com
    Thanks in advance.

    Hi,
    It’s not recommended to use LMHOSTS file. Instead, we can use conditional forwarders or secondary DNS zones for DNS resolution between the
    two forests. Besides, we need to open required ports for building inter-forest trust.
    Regarding how to configure name resolution between two forests, the following article can be referred to for more information.
    Trust relationship between Two external forest / Name Resolution
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/f0f384c5-f421-4592-88db-409c171b0567/trust-relationship-between-two-external-forest-name-resolution?forum=winserverDS
    Best regards,
    Frank Shen

  • Certificate trust issues - is there any workaround?

    I'm an IT Engineer in big company and i often see annoying troubles with Wi-Fi connection and secured (SSL) SMTP in Mac OS X.
    Some MacBooks works fine, some with exactly the same software version cannot trust certificates of our authorization server for wi-fi and also cannot send mail via SMTP with SSL (i think this is trust issue too).
    So now i have in front of me MacBook Air with Mac Os X 10.6.8. It had worked well but now it has same issue with mail and wi-fi at same time. So i think it have one reason. It also tell me that Mail server certificate is out of date after 11 May 2011, but actually there is a new cert on server issued 12 May 2011.
    Sooo, what a f^%% is going on?
    Any ideas why and what to do?

    Yeah, but its custom coding in conjunction with a 3rd party for the postcode lookup. You also then need to handle the annoying dom manipulation BC does with its code on things like discount code fields, shipping option changes etc effecting your code. You really need to have a good understanding of coding AND BC in this case unfortunatly.
    Possible though, but if you do not want to pay for it to be done or not able to do it yourself - Best to avoid this if you can on the project.

  • TS1398 I am unable to connect wifi on my phone 4s since last 2 weeks... I am living in shanghai and did not have this issue since 2 weeks... iPad works fine... Please suggest some measures... Tried the on off reset settings etc.

    I am unable to connect wifi on my phone 4s since last 2 weeks... I am living in shanghai and did not have this issue since 2 weeks... iPad works fine... Please suggest some measures... Tried the on off reset settings etc. but no luck ...
    In fact after updating the software to the latest version I am having more of this... Sometimes the wifi button freezes an I can't even slide it to on / off...
    Thanks

    Noooo! Actually I too had d same prob wit my iPhone 4S. When I connect to my wifi network it won't get connected or it wil be grey scaled! I took it to d istore and since I had warranty they replaced my IPhone. It iPad charger has high volt than ur iPhone charger so when u connect wit it, there is a chance where large amount of current passes thru ur iPhone. So for sure it wil damage ur motherboard and its parts! Many said that iOS 6 or 6.0.1 or 6.1 was d reason for tis wifi prob! But apple never made its mistake wit it's software. If and only if u hav hardware prob u wil hav these sort of wifi prob Bluetooth prob! So best way s to replace ur iPhone!

  • Issue with DEBMAS IDoc,not all fields are reflected in the IDoc Seg E1KNB1M

    For IDoc type DEBMAS, there is a segment E1KNB1M. This segment is relate to the customer correspondence details (XD02 -> company code data -> Correspondence).
    For any change to the customer master a DEBMAS IDoc is triggered which has data in segments including the E1KNB1M.
    In my case for few customers, the not all fields in the segment E1KNB1M contain data. Few fields contain data but the rest are filled with u2018\u2019. This is happening only in the production system, for the same customer in the quality system the data is there as required.
    I checked in debugging, and found that the data is correctly passed to the segment in program SAPLVV01 Include LVV01F01. And the segment contains data till the IDoc is triggered.  I.e. the fields are not getting cleared at any point.
    Can anyone suggest what is happening and how to fix this? Please note that the issue is only in the production system and not in the quality system ( for the same customer).

    BTT... Need some help on the above

  • ESPN only not working properly (not from "blackout" issue).

    Both of my ESPN channels become fuzzy or just go to unavailable entirely.  It's not a "blackout" issue.  For example I am watching sportscenter right now and the channel goes in and out, freezes up, etc.  ESPN works fine on my bedroom tv.  I have also received a new box to switch out to see if it was a box problem, but the other box does the exact same thing. 
    Again, it's only the one channel.  Any ideas?

    Retighten all coax connectors to the STB, including any splitters in the signal path.  What you describe appears to be a frequency-related problem (I think the two ESPN channels are on the same QAM channel) that loose coax connectors can cause.  It's a physics thing  that can effect only certain frequencies.  This is a solution other have been successfully used to fix problems were only a few channels break up or go away.

  • Having horrible service with 4GLTE I have had 3G for several weeks (I am not the only person I know having this problem), I have reset my network settings and it did not resolve the issue.  I am also unable to send SMS and text messages without them eithe

    Having horrible service with 4GLTE I have had 3G for several weeks (I am not the only person I know having this problem), I have reset my network settings and it did not resolve the issue.  I am also unable to send SMS and text messages without them either failing or not sending at all.  Is there an outage in the Cleveland, Ohio area (zip codes 44129, 44134, 44137) or anything else I can do to resolve this issue?

    Not that I'm a Verizon employee, but I have experience in the field. An LTE tower will only extend up to, on a perfect day, with no elevation, 6-7 miles. On a typical day, you will be lucky at four (4) miles. The three ZIP codes you've given are all within about a 12 mile radius. That would mean that 2-3 towers are currently down at the same time, and Verizon would know about it within the hour. Being it's Cleveland, I'm sure they would receive numerous calls regarding an outage of that size.
    My point is that if you're having issues in all three ZIP codes, chances are it's a phone issue. If you're handset is simply not receiving LTE, but still receiving 3G, that would signify a SIM card issue. You need to get your SIM card replaced.

  • I am running on OSX 10.10.1 and have a 2009 imac intel and I am having severe latency issues.  I am not familiar with macs as this is my home computer used by other family members.  Any help on how to troubleshoot why such latency issues?

    I am running on OSX 10.10.1 and have a 2009 imac intel and I am having severe latency issues.  I am not familiar with macs as this is my home computer used by other family members.  Any help on how to troubleshoot why such latency issues?

    When you see a beachball cursor or the slowness is especially bad, note the exact time: hour, minute, second.  
    These instructions must be carried out as an administrator. If you have only one user account, you are the administrator.
    Launch the Console application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad and start typing the name.
    The title of the Console window should be All Messages. If it isn't, select
              SYSTEM LOG QUERIES ▹ All Messages
    from the log list on the left. If you don't see that list, select
              View ▹ Show Log List
    from the menu bar at the top of the screen.
    Each message in the log begins with the date and time when it was entered. Scroll back to the time you noted above.
    Select the messages entered from then until the end of the episode, or until they start to repeat, whichever comes first.
    Copy the messages to the Clipboard by pressing the key combination command-C. Paste into a reply to this message by pressing command-V.
    The log contains a vast amount of information, almost all of it useless for solving any particular problem. When posting a log extract, be selective. A few dozen lines are almost always more than enough.
    Please don't indiscriminately dump thousands of lines from the log into this discussion.
    Please don't post screenshots of log messages—post the text.
    Some private information, such as your name, may appear in the log. Anonymize before posting.

  • My Iphone calendar events are not showing up in iCal when I sync? Syncing has not been an issue till today?

    My Iphone calendar events are not showing up in iCal when I sync? Syncing has not been an issue till today?

    I found this tip from a 2011 discussion on the same topic.
    Open iCal and backup or export your entries. Make a note of the fie name and location, you're going to need them in a minute. Once your backup/export is completed, close the iCal application.
    Open Finder and remove everything inside the "Username/Library/Calendars" folder. For instance, if your username is "Joe", then move everything inside the "Joe/Library/Calendars" folder.
    Open the iSync application. It's located in the "/Applications/" folder. Once iSync is opened, go into the iSync Preferences (iSync -> Preferences) and push/click the "Reset Sync History" button. Then, close the iSync application.
    Re-Open the iCal application and Import (File -> Import) a new calendar. When prompted, use your notes from Step #1 to select the file your created earlier. Once completed, close the iCal application (you should have all of your calendar entries back.)
    Open the iTunes application and connect your Apple iPhone to the computer.
    Within the Advanced section of the Info tab for the Apple iPhone, check the box the overwrites/replaces the Calendar data on the Apple iPhone.
    Click the Apple/Sync button. New, modified and deleted entries should now be syncing correctly.
    That's it! You should be all set and iTunes, iCal and our Apple iPhone should all be playing nicely as friends again. We've used the exact method to repair our own Apple iPhone at least once... maybe even twice.

  • I have not had any issue with Itunes on my PC until recently. Every now and then my Itunes library appears on my screen?  I have not clicked the itunes icon beforehand nor plugged in my Ipod Touch?  Why does ths happen please. I have windows XPPOdany ic

    I have not had any issue with Itunes on my PC until very recently. Every now and then my Itunes library appears on my screen?  I have not clicked the itunes icon beforehand nor plugged in my Ipod Touch?  Why does this happen please as it is driving me crazy!.

    What's the precise text of the message, please? (There's a couple of different ones I can think of that you might be getting.)

Maybe you are looking for

  • Notification Center Deleting Messages

    I recently updated to ios7 from my iphone 4s and everytime a notification pops up and I choose to hide it by flicking up...the notication along with the content from the app it came from deletes itself when I try to go look for it. This has happened

  • Where is the restore button for iPhones on the new version of itunes

    I have bought an iPhone 4 which was on orange ee. The friend has paid them to unlock it and they confirmed it has been done but my voda sim shows no service. The instructions from ee mention restore from iTunes but the new version doesn't appear to h

  • Logon to system is not working in ChaRM solman 7.1sp2

    Hello, I have configured Urgent change in solman 7.1sp2 version. Logon to system is not working in Landscape bar. Please help on this. Regards, Karthik

  • Using multiple headphones with apple tv and projector?

    Hi, I own a Barbers where we have an apple tv set up with a projector (through HDMI). It would probably be a good point to say this is attached to the ceiling As we're trying to take things to the next level, i was wanting to provide over-ear headpho

  • Calculating colour percentages

    Is there a way of viewing what percentage of your canvas a single colour uses? For example, if i have a design that's red, blue and yellow, is there a way to see a percentage of how much each colour value is present? (Ie. 20% red, 35% blue, 45% yello