AD FS - Certificate Authentication - no valid certificate found

HanakJ 86 Reputation points
2022-07-28T11:51:48.12+00:00

Hello,

I have one AD FS server (OS: Windows Server 2016).
I created user certificate and import to SmartCard.

I want to authenticate against AD FS with user Certificate on SmartCard. On AD FS server I setup this:
225822-image.png

On test AD FS login page I can see the options to Sign in using a certificate, when I select this options I will get this error:
225776-image.png

I tested this internaly on AD FS server.
Any ideas where could be a problem?

Thanks a lot guys

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,854 questions
Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,189 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,721 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 33,801 Reputation points Microsoft Employee
    2022-08-02T23:16:45.087+00:00

    Hi @HanakJ ,

    Thanks for your post and for sharing the screenshots. As mentioned in the error "No valid certificate found", this happens if you are either missing an SSL certificate on the AD FS server itself or need to renew an expired one.

    If you already did this and your certificate was recently issued, it may take three to six days for the certificate to be validated.

    To deploy a new SSL certificate to your AD FS server, you can follow the guide, Managing SSL Certificates in AD FS and WAP in Windows Server 2016

    To replace an existing certificate, you can follow the guide, Update the TLS/SSL certificate for an Active Directory Federation Services (AD FS) farm

    -

    If the information provided was helpful to you, please Accept the answer. This will help us and other community members as well.

    0 comments No comments