You are viewing limited content. For full access, please sign in.

Question

Question

ID4037: The key needed to verify the signature could not be resolved

asked on May 7 • Show version history

I have been troubleshooting this issue with WebLink for a couple of weeks now with no resolution. I have opened a support case with Laserfiche as well but wanted to put it out here for the community in case someone else has had this issue with WebLink and has some suggestions and if I find a resolution I will post it here for others.

We have WebLink 11 Update 6 installed on 3 load balanced servers. Up until about 2-3 weeks ago it was working without any issues. Around that time after users authenticated with LFDS, it takes them to a WebLink error page:

On the WebLink server the following warning is recorded in Event Viewer\Applications and Services Logs\Laserfiche\Portal\Server\Operational.
 

Log Name:      Laserfiche-Portal-Server/Operational
Source:        Laserfiche-Portal-Server
Date:          5/6/2026 7:56:13 PM
Event ID:      14
Task Category: ImportantWarning
Level:         Warning
Keywords:      Session0,Session1,Session2,Session3
User:          IIS APPPOOL\WebLinkAppPool
Computer:      XXXX
Description:
Operation: /WebLink/
  Message: Exception encountered, stack trace:\r\n  System.Web.HttpApplication.RaiseOnError\r\n  System.Web.HttpApplication.RecordError\r\n  System.Web.PipelineStepManager.ResumeSteps\r\n  System.Web.HttpApplication.BeginProcessRequestNotification\r\n  System.Web.HttpRuntime.ProcessRequestNotificationPrivate\r\n  System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper\r\n  System.Web.Hosting.PipelineRuntime.ProcessRequestNotification\r\n  System.Web.Hosting.UnsafeIISMethods.MgdIndicateCompletion\r\n  System.Web.Hosting.UnsafeIISMethods.MgdIndicateCompletion\r\n  System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper\r\n  System.Web.Hosting.PipelineRuntime.ProcessRequestNotification\r\nException details:\r\n  Caught exception SignatureVerificationFailedException, Message: ID4037: The key needed to verify the signature could not be resolved from the following security key identifier 'SecurityKeyIdentifier\r\n    (\r\n    IsReadOnly = False,\r\n    Count = 1,\r\n    Clause[0] = System.IdentityModel.Tokens.Saml2SecurityKeyIdentifierClause\r\n    )\r\n'. Ensure that the SecurityTokenResolver is populated with the required key.\r\n  Stack trace:    at System.IdentityModel.EnvelopedSignatureReader.ResolveSigningCredentials()\r\n   at System.IdentityModel.EnvelopedSignatureReader.OnEndOfRootElement()\r\n   at System.IdentityModel.EnvelopedSignatureReader.Read()\r\n   at System.Xml.XmlReader.ReadEndElement()\r\n   at System.IdentityModel.Tokens.Saml2SecurityTokenHandler.ReadAssertion(XmlReader reader)\r\n   at System.IdentityModel.Tokens.Saml2SecurityTokenHandler.ReadToken(XmlReader reader)\r\n   at System.IdentityModel.Tokens.SecurityTokenHandlerCollection.ReadToken(XmlReader reader)\r\n   at System.IdentityModel.Services.TokenReceiver.ReadToken(String tokenXml, XmlDictionaryReaderQuotas readerQuotas, FederationConfiguration federationConfiguration)\r\n   at System.IdentityModel.Services.WSFederationAuthenticationModule.SignInWithResponseMessage(HttpRequestBase request)\r\n   at System.IdentityModel.Services.WSFederationAuthenticationModule.OnAuthenticateRequest(Object sender, EventArgs args)\r\n   at System.Web.HttpApplication.SyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()\r\n   at System.Web.HttpApplication.ExecuteStepImpl(IExecutionStep step)\r\n   at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)\r\n

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Laserfiche-Portal-Server" Guid="{7DCFE07A-D2F9-5FCB-2720-8B35AC94BD41}" />
    <EventID>14</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>65520</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000f00000000000</Keywords>
    <TimeCreated SystemTime="2026-05-07T02:56:13.292827400Z" />
    <EventRecordID>1141775</EventRecordID>
    <Correlation />
    <Execution ProcessID="4684" ThreadID="5760" />
    <Channel>Laserfiche-Portal-Server/Operational</Channel>
    <Computer>XXXX</Computer>
    <Security UserID="XXXX" />
  </System>
  <EventData>
    <Data Name="message">Operation: /WebLink/
  Message: Exception encountered, stack trace:\r\n  System.Web.HttpApplication.RaiseOnError\r\n  System.Web.HttpApplication.RecordError\r\n  System.Web.PipelineStepManager.ResumeSteps\r\n  System.Web.HttpApplication.BeginProcessRequestNotification\r\n  System.Web.HttpRuntime.ProcessRequestNotificationPrivate\r\n  System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper\r\n  System.Web.Hosting.PipelineRuntime.ProcessRequestNotification\r\n  System.Web.Hosting.UnsafeIISMethods.MgdIndicateCompletion\r\n  System.Web.Hosting.UnsafeIISMethods.MgdIndicateCompletion\r\n  System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper\r\n  System.Web.Hosting.PipelineRuntime.ProcessRequestNotification\r\nException details:\r\n  Caught exception SignatureVerificationFailedException, Message: ID4037: The key needed to verify the signature could not be resolved from the following security key identifier 'SecurityKeyIdentifier\r\n    (\r\n    IsReadOnly = False,\r\n    Count = 1,\r\n    Clause[0] = System.IdentityModel.Tokens.Saml2SecurityKeyIdentifierClause\r\n    )\r\n'. Ensure that the SecurityTokenResolver is populated with the required key.\r\n  Stack trace:    at System.IdentityModel.EnvelopedSignatureReader.ResolveSigningCredentials()\r\n   at System.IdentityModel.EnvelopedSignatureReader.OnEndOfRootElement()\r\n   at System.IdentityModel.EnvelopedSignatureReader.Read()\r\n   at System.Xml.XmlReader.ReadEndElement()\r\n   at System.IdentityModel.Tokens.Saml2SecurityTokenHandler.ReadAssertion(XmlReader reader)\r\n   at System.IdentityModel.Tokens.Saml2SecurityTokenHandler.ReadToken(XmlReader reader)\r\n   at System.IdentityModel.Tokens.SecurityTokenHandlerCollection.ReadToken(XmlReader reader)\r\n   at System.IdentityModel.Services.TokenReceiver.ReadToken(String tokenXml, XmlDictionaryReaderQuotas readerQuotas, FederationConfiguration federationConfiguration)\r\n   at System.IdentityModel.Services.WSFederationAuthenticationModule.SignInWithResponseMessage(HttpRequestBase request)\r\n   at System.IdentityModel.Services.WSFederationAuthenticationModule.OnAuthenticateRequest(Object sender, EventArgs args)\r\n   at System.Web.HttpApplication.SyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()\r\n   at System.Web.HttpApplication.ExecuteStepImpl(IExecutionStep step)\r\n   at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean&amp; completedSynchronously)\r\n
</Data>
  </EventData>
</Event>

What has been done?

  • I spoke with a few people at Empower and it was suggested to replace the WebLink licenses, which I have done and no dice.
  • I have also uninstalled and reinstalled WebLink while deleting the Program Files WebLink folder in-between to make sure nothing was left over.
  • I have deleted the licenses in LFDS and created brand new ones.
  • I have verified that TLS 1.2 settings are set according to the LF Support KB Article.

I do not believe it is LFDS because we have a separate NLB of WebLink for our Canada instance that uses the same LFDS and LFDSSTS and it does not have this problem. Forms and the Web Client are installed on the same servers as WebLink and they are also working without any issues.

I have seen this error before with the Web Client, but that was in a DMZ and it was a DNS setting that needed to be added to the web.config files. These servers are all internal.

If anyone has any suggestions or ideas, please let me know.

UPDATE: Our Canada WebLink servers are now experiencing the same problem. We have not made any changes to the certs or anything else to the Canada servers.

0 0

Replies

replied on May 7

I think you mentioned that the problems started around the time that you rotated TLS certs. Do you have the old ones to compare? I would wonder if there is a missing SAN or something. If it is related to that, you might try to get a Wireshark trace from the WebLink machine during a quiet time and see if there are any attempted connections (https or otherwise) from the WebLink machine to the LFDS machine.

0 0
replied on May 7

Hi Brian, I originally thought that we had changed the TLS certs around the time this started happening, but after looking at when the certs were put in place, that is not the case. The certs were renewed 02/26/2026, so if that's what caused the issue it would have happened sooner.

0 0
replied on May 7

I still think it's something about WebLink not having or getting the current token signing key. If you look in the various lf.licx files, do they have the same <TokenSigningKey>?

0 0
replied on May 8

We have Forms and the Web Client on the same server as WebLink, so I checked the <TokenSigningKey> values between the 3 license files and they all are identical. Forms and Web Client are working as expected.

0 0
replied on May 8

is it possible your identity provider did a key rotation and weblink is still using the older cached key?  Entra ID for example, periodically rotates its token-signing certificates automatically.

Since your environment is load balanced, do you have a way to test each node separately (possibly temporarily remove one node at a time to see if its node specific).  This would indicates a possible configuration mismatch between any of the load balanced servers?

0 0
replied on May 11

We get the error when using Windows accounts as well.

0 0
replied on May 7

Do you have any corresponding events in the LFDS or STS logs in the event viewer? Or .NET stuff under the main Windows application logs?

0 0
replied on May 7

Nope

0 0
replied on May 12 • Show version history

The plot thickens. I was able to figure out that on our Canada servers we have 1 of 2 WebLink servers that are working/not working. Today I also remembered that we have 2 instances of WebLink configured on both servers /WebLink and /PDIWebLink. /WebLink works on 1 server and not the other. /PDIWebLink works on both. They are both configured in the Default Website in IIS.

0 0
replied on May 14 • Show version history

I have made some progress. In the XmlEndpointUtility on the LFDS server I updated the "Signature method for SSO token" from "SHA1" to "SHA256" and that has fixed the issue on the second Canada WebLink server. The 3 US servers however are still getting the same error.

replied on May 18

In case anyone wants to take a look at the Laserfiche Support case or needs to reference it for other customers later, it is case #28333.

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.