Can't sign in to Outlook on the web or the EAC if the Exchange Server OAuth certificate is expired

Original KB number:   2617816

Summary

This article discusses an error that occurs when signing in to Outlook on the web or the Exchange Admin Center (EAC) in Exchange Server. This issue occurs if the Exchange Server Open Authentication (OAuth) certificate is expired, not present, or incorrectly configured. To fix this issue, install the recommended update.

Symptoms

When you sign in to Outlook on the web or the EAC in Exchange Server, the web browser freezes or reports that the redirect limit was reached. Event 1003 is also logged in the event viewer as shown in the following example:

Event ID: 1003
Source: MSExchange Front End HTTPS Proxy
[Owa] An internal server error occurred. The unhandled exception was: System.NullReferenceException: Object reference not set to an instance of an object.
at Microsoft.Exchange.HttpProxy.FbaModule.ParseCadataCookies(HttpApplication httpApplication)

Cause

This issue occurs if the OAuth certificate is expired, not present, or incorrectly configured.

Resolution

To fix this issue, install the appropriate update: