Search code examples

WIF Based Authentication Does Not Contact STS Issuer

I am attempting to build an 4.7 (v4.5 WIF) using claims based authentication against our internal STS server. We have older working .Net apps (< 4.5) that can successfully get claims.

The issue is that the new app never contacts the STS server.

I surmise the failure is in how I am setting up the federation web.config vs the old. Here is my latest config, non working, followed by a config that works using the old identity process (WIF 3.5).

V4.0 WIF web.config (New 4.7 project)
            <add value="urn:jabberwocky" />
        <issuerNameRegistry type="System.IdentityModel.Tokens.ConfigurationBasedIssuerNameRegistry, System.IdentityModel, Version=, Culture=neutral, PublicKeyToken=b77a5c561934e089">
                <add thumbprint="{MyThumbprint}" name="https://{MyIssuerURL}" />
        <certificateValidation certificateValidationMode="None" />
        <cookieHandler requireSsl="false" />
        <wsFederation passiveRedirectEnabled="true"
                        requireHttps="true" />
V3.5 WIF web.config (Old 4.0 project)
      <add value="urn:Jabberwocky" />
    <certificateValidation certificateValidationMode="None" />
    <claimsAuthenticationManager type="{Namespace}.MyAuthenticationManager, {Namespace}" />
      <wsFederation passiveRedirectEnabled="true" 
                    realm="urn:Jabberwocky" />
      <cookieHandler requireSsl="true" />
    <issuerNameRegistry type="Microsoft.IdentityModel.Tokens.ConfigurationBasedIssuerNameRegistry, Microsoft.IdentityModel, Version=, Culture=neutral, PublicKeyToken=31bf3856ad364e35">
        <add thumbprint="{MyThumbprint}" name="https://{MyIssuerURL}" />

  • I know it does not hit the STS server because I use an invalid audienceUris value as a test, and I don't get rejected by the server as I would in the old project.
  • I sense it has something to do with the missing federatedAuthentication value in the old but not found in the new.


  • As for your current config, make sure both SAM and FAM modules are there.

    If you want to control what's going on, I suggest switching to programmatic approach. Take a look at my tutorial.