Federation Service Communication

Applies To: Windows Server 2008 R2

Federation Service communication is communication between federation servers and Web servers that host the claims-aware agent. The Web server should be updated from the Federation Service. Federation Service communication fails when the Active Directory Federation Services (AD FS) Web Agent cannot be updated.

Events

Event ID Source Message

619

Microsoft-Windows-ADFS

The AD FS Web Agent was unable to update trust information from the Federation Service. A serious error has occurred.
Federation Service URL: %1

If this failure occurs during startup, no users will be authenticated until the Federation Service can be contacted. If the Federation Service cannot be contacted, the Web agent will continue to authenticate users with the existing trust information, and it will attempt this operation again at a later time.

This condition occurs when an unexpected exception is thrown from the GetFsTrustInformation Web method call to the Federation Service.

Additional Data
Exception information:
%2

620

Microsoft-Windows-ADFS

The AD FS Web Agent was unable to update trust information from the Federation Service. A Hypertext Transfer Protocol (HTTP) or networking error has occurred.
Federation Service URL: %1
WebExceptionStatus value: %2
WebException message: %3

If this failure occurs during startup, no users will be authenticated until the Federation Service can be contacted. If the Federation Service cannot be contacted, the Web agent will continue to be authenticated users with the existing trust information, and it will attempt this operation again at a later time.

User Action
Verify that the Federation Service Uniform Resource Locator (URL) is properly configured, the Federation Service is started, and the Federation Service can be contacted from this computer.

684

Microsoft-Windows-ADFS

The AD FS Web Agent was unable to update trust information from the Federation Service. The Federation Service Secure Sockets Layer (SSL) server certificate could not be validated.
Federation Service URL: %1

User Action
Verify that the Federation Service SSL server certificate chains to a root certificate that is in the Local Computer Trusted Root Certification Authorities certificate store on the web server.

Verify that the SSL certificate is neither expired nor revoked.

Verify that the SSL certificate subject matches the host name portion of the Federation Service Uniform Resource Locator (URL).

691

Microsoft-Windows-ADFS

The AD FS Web Agent was unable to update trust information from the Federation Service. The Federation Service returned an error.
Federation Service URL: %1

User Action
Ensure that the Federation service is properly configured and started.

Additional Data
SoapException error message:
%2

713

Microsoft-Windows-ADFS

The AD FS Web Agent was unable to update trust information from the Federation Service. An InvalidOperationException occurred.
Federation Service URL: %1

User Action
Ensure that the Federation Service is properly configured and started.

Additional Data
InvalidOperationException error message:
%2

Web Agent for Claims-Aware Applications

Active Directory Federation Services