Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8814135
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 14, 20262026-06-14T04:01:59+00:00 2026-06-14T04:01:59+00:00

Why am I getting this error and what exactly does it mean? Is there

  • 0

Why am I getting this error and what exactly does it mean? Is there something else this could be besides a mismatched cert setup?

I have a locally-running Unit Test that hits an ADFS Proxy at our data center for Active Federation and then hits our WCF web service running in Azure (web role). The client errors out with a MessageSecurityException. So looking at the server’s service logs, it logs the exception:

Cannot resolve KeyInfo for decryption: KeyInfo 'SecurityKeyIdentifier
    (
    IsReadOnly = False,
    Count = 1,
    Clause[0] = EncryptedKeyIdentifierClause(EncryptedKey = abcdefg123456==, Method 'http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p')
    )
', available tokens 'System.ServiceModel.Security.AggregateTokenResolver'.

EVERYTHING I find online about this says that I have a certificate mismatch between the client and server. But I’ve double-, triple-, and quadruple-checked these cert references and they’re identical. The client’s (local unit test) endpoint:

  <endpoint address="https://mydomain.com/TestService.svc"
            binding="customBinding"
            bindingConfiguration="WS2007FederationHttpBinding_ISayHelloService"
            contract="ActiveFederationHelpers.Tests.ISayHelloService"
            name="WS2007FederationHttpBinding_ISayHelloService">
    <identity>
      <certificateReference findValue="D4ECD7FF6A551FAA040BA0B62B77B8EA0F11CD16"
                            storeLocation="LocalMachine"
                            storeName="My"
                            x509FindType="FindByThumbprint" />
    </identity>
  </endpoint>

My server’s service config (I RDP’d into an Azure instance to pull from there to confirm it’s really what I think it is):

<serviceCertificate>
    <certificateReference findValue="D4ECD7FF6A551FAA040BA0B62B77B8EA0F11CD16" storeLocation="LocalMachine" storeName="My" x509FindType="FindByThumbprint" />
</serviceCertificate>

I’ve confirmed that these certs are installed both on my local machine (unit test) and the Azure server (web service server). And I’ve even confirmed that the thumbprint are what’s in my config. I have this all running successfully in a local environment. The ONLY differences are certs, URIs, and the introduction of Azure.

A few other things I’ve double-checked:

  1. No, I didn’t copy/paste the thumbprint with the unicode chars in there. I’m reusing my SSL cert for my services and SSL works perfectly so it’s not a typo in the thumbprint.
  2. There is no older or alternative version of this cert that might be confusing me. Like I said, I’ve been inspecting the cert’s thumbprints (in MMC -> Certs) every time I ensure it’s installed.
  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-14T04:02:01+00:00Added an answer on June 14, 2026 at 4:02 am

    Ultimately, ADFS was misconfigured and somehow this was the resulting error. The misconfiguration was due to my Federation Service Name not being a hostname that resolved to the ADFS Proxy (just the ADFS server itself). Rearchitecting our ADFS setup around our public Proxy’s hostname resolved these problems for us.

    I suspect the reason this wasn’t an issue outside of Azure was because the Federation Service Name resolved to the internal server and not the external proxy and Azure only had access to the external proxy.

    Either way, moral of the story (that nearly nobody seems to talk about) is that your Federation Service Name must be a public URI if you expect to ever use a Proxy with it, and that Proxy must resolve to that public URI!

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I keep getting this error and have no idea why. I googled and scanned
What exactly does this mean? * Terminating app due to uncaught exception 'NSInternalInconsistencyException', reason:
Getting this error: 2009-09-03 12:44:02.307 xcodebuild[307:10b] warning: compiler 'com.apple.compilers.llvm.clang.1_0.analyzer' is based on missing compiler
Getting this error with jquery & jquery.form. Site has been live for awhile..upgraded to
Getting this error when try to add an item to my repositories/context: Collection has
Am getting this error message and matched my brackets and couldn't find anything wrong.
I´m getting this error while trying to commit to a svn repository: svn: MKACTIVITY
Keep getting this error after inserting a subdatasheet into a query and trying to
am getting this error when i open my site in internet explorer......... plz help
Am getting this error for my code: Undefined symbols for architecture x86_64: _spendDollars, referenced

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.