I have been troubleshooting this issue with WebLink for a couple of weeks now with no resolution. I have opened a support case with Laserfiche as well but wanted to put it out here for the community in case someone else has had this issue with WebLink and has some suggestions and if I find a resolution I will post it here for others.
We have WebLink 11 Update 6 installed on 3 load balanced servers. Up until about 2-3 weeks ago it was working without any issues. Around that time after users authenticated with LFDS, it takes them to a WebLink error page:
On the WebLink server the following warning is recorded in Event Viewer\Applications and Services Logs\Laserfiche\Portal\Server\Operational.
Log Name: Laserfiche-Portal-Server/Operational
Source: Laserfiche-Portal-Server
Date: 5/6/2026 7:56:13 PM
Event ID: 14
Task Category: ImportantWarning
Level: Warning
Keywords: Session0,Session1,Session2,Session3
User: IIS APPPOOL\WebLinkAppPool
Computer: XXXX
Description:
Operation: /WebLink/
Message: Exception encountered, stack trace:\r\n System.Web.HttpApplication.RaiseOnError\r\n System.Web.HttpApplication.RecordError\r\n System.Web.PipelineStepManager.ResumeSteps\r\n System.Web.HttpApplication.BeginProcessRequestNotification\r\n System.Web.HttpRuntime.ProcessRequestNotificationPrivate\r\n System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper\r\n System.Web.Hosting.PipelineRuntime.ProcessRequestNotification\r\n System.Web.Hosting.UnsafeIISMethods.MgdIndicateCompletion\r\n System.Web.Hosting.UnsafeIISMethods.MgdIndicateCompletion\r\n System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper\r\n System.Web.Hosting.PipelineRuntime.ProcessRequestNotification\r\nException details:\r\n Caught exception SignatureVerificationFailedException, Message: ID4037: The key needed to verify the signature could not be resolved from the following security key identifier 'SecurityKeyIdentifier\r\n (\r\n IsReadOnly = False,\r\n Count = 1,\r\n Clause[0] = System.IdentityModel.Tokens.Saml2SecurityKeyIdentifierClause\r\n )\r\n'. Ensure that the SecurityTokenResolver is populated with the required key.\r\n Stack trace: at System.IdentityModel.EnvelopedSignatureReader.ResolveSigningCredentials()\r\n at System.IdentityModel.EnvelopedSignatureReader.OnEndOfRootElement()\r\n at System.IdentityModel.EnvelopedSignatureReader.Read()\r\n at System.Xml.XmlReader.ReadEndElement()\r\n at System.IdentityModel.Tokens.Saml2SecurityTokenHandler.ReadAssertion(XmlReader reader)\r\n at System.IdentityModel.Tokens.Saml2SecurityTokenHandler.ReadToken(XmlReader reader)\r\n at System.IdentityModel.Tokens.SecurityTokenHandlerCollection.ReadToken(XmlReader reader)\r\n at System.IdentityModel.Services.TokenReceiver.ReadToken(String tokenXml, XmlDictionaryReaderQuotas readerQuotas, FederationConfiguration federationConfiguration)\r\n at System.IdentityModel.Services.WSFederationAuthenticationModule.SignInWithResponseMessage(HttpRequestBase request)\r\n at System.IdentityModel.Services.WSFederationAuthenticationModule.OnAuthenticateRequest(Object sender, EventArgs args)\r\n at System.Web.HttpApplication.SyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()\r\n at System.Web.HttpApplication.ExecuteStepImpl(IExecutionStep step)\r\n at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)\r\n
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Laserfiche-Portal-Server" Guid="{7DCFE07A-D2F9-5FCB-2720-8B35AC94BD41}" />
<EventID>14</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>65520</Task>
<Opcode>0</Opcode>
<Keywords>0x8000f00000000000</Keywords>
<TimeCreated SystemTime="2026-05-07T02:56:13.292827400Z" />
<EventRecordID>1141775</EventRecordID>
<Correlation />
<Execution ProcessID="4684" ThreadID="5760" />
<Channel>Laserfiche-Portal-Server/Operational</Channel>
<Computer>XXXX</Computer>
<Security UserID="XXXX" />
</System>
<EventData>
<Data Name="message">Operation: /WebLink/
Message: Exception encountered, stack trace:\r\n System.Web.HttpApplication.RaiseOnError\r\n System.Web.HttpApplication.RecordError\r\n System.Web.PipelineStepManager.ResumeSteps\r\n System.Web.HttpApplication.BeginProcessRequestNotification\r\n System.Web.HttpRuntime.ProcessRequestNotificationPrivate\r\n System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper\r\n System.Web.Hosting.PipelineRuntime.ProcessRequestNotification\r\n System.Web.Hosting.UnsafeIISMethods.MgdIndicateCompletion\r\n System.Web.Hosting.UnsafeIISMethods.MgdIndicateCompletion\r\n System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper\r\n System.Web.Hosting.PipelineRuntime.ProcessRequestNotification\r\nException details:\r\n Caught exception SignatureVerificationFailedException, Message: ID4037: The key needed to verify the signature could not be resolved from the following security key identifier 'SecurityKeyIdentifier\r\n (\r\n IsReadOnly = False,\r\n Count = 1,\r\n Clause[0] = System.IdentityModel.Tokens.Saml2SecurityKeyIdentifierClause\r\n )\r\n'. Ensure that the SecurityTokenResolver is populated with the required key.\r\n Stack trace: at System.IdentityModel.EnvelopedSignatureReader.ResolveSigningCredentials()\r\n at System.IdentityModel.EnvelopedSignatureReader.OnEndOfRootElement()\r\n at System.IdentityModel.EnvelopedSignatureReader.Read()\r\n at System.Xml.XmlReader.ReadEndElement()\r\n at System.IdentityModel.Tokens.Saml2SecurityTokenHandler.ReadAssertion(XmlReader reader)\r\n at System.IdentityModel.Tokens.Saml2SecurityTokenHandler.ReadToken(XmlReader reader)\r\n at System.IdentityModel.Tokens.SecurityTokenHandlerCollection.ReadToken(XmlReader reader)\r\n at System.IdentityModel.Services.TokenReceiver.ReadToken(String tokenXml, XmlDictionaryReaderQuotas readerQuotas, FederationConfiguration federationConfiguration)\r\n at System.IdentityModel.Services.WSFederationAuthenticationModule.SignInWithResponseMessage(HttpRequestBase request)\r\n at System.IdentityModel.Services.WSFederationAuthenticationModule.OnAuthenticateRequest(Object sender, EventArgs args)\r\n at System.Web.HttpApplication.SyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()\r\n at System.Web.HttpApplication.ExecuteStepImpl(IExecutionStep step)\r\n at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)\r\n
</Data>
</EventData>
</Event>
What has been done?
- I spoke with a few people at Empower and it was suggested to replace the WebLink licenses, which I have done and no dice.
- I have also uninstalled and reinstalled WebLink while deleting the Program Files WebLink folder in-between to make sure nothing was left over.
- I have deleted the licenses in LFDS and created brand new ones.
- I have verified that TLS 1.2 settings are set according to the LF Support KB Article.
I do not believe it is LFDS because we have a separate NLB of WebLink for our Canada instance that uses the same LFDS and LFDSSTS and it does not have this problem. Forms and the Web Client are installed on the same servers as WebLink and they are also working without any issues.
I have seen this error before with the Web Client, but that was in a DMZ and it was a DNS setting that needed to be added to the web.config files. These servers are all internal.
If anyone has any suggestions or ideas, please let me know.
UPDATE: Our Canada WebLink servers are now experiencing the same problem. We have not made any changes to the certs or anything else to the Canada servers.