Hi,
My ADFS server has auto-generated a new token-signing certificate as expected.
Currently it is still secondary, but will be promoted to primary in a week or so.
I've exported the new certificate (DER encoded) and uploaded onto the admin console of a couple of Relying Party Trusts.
In the past this is all I've had to do but for some reason this time the applications don't like it. Typical error is "Failed: Signature Invalid". The SAML assertion validator also reports Signature issues.
My understanding is that both primary and secondary certificates should work for a period.
Any suggestions welcome.