PartialChain: A certificate chain could not be built to a trusted root authority.
Applies to SharePoint 2016; not tested on other versions of SharePoint.
Symptoms
Windows Application Event Viewer shows two certificate-related errors every minute as follows:
Event ID 8306
An exception occurred when trying to issue security token: ID3242: The security token could not be authenticated or authorized..
Event ID 8311
An operation failed because the following certificate has validation errors:
Subject Name: CN=SharePoint Security Token Service, OU=SharePoint, O=Microsoft, C=US
Issuer Name: CN=SharePoint Root Authority, OU=SharePoint, O=Microsoft, C=US
Thumbprint: 8C0669A6945F6A310538F1F8159D541CBDFE9427
Errors:
PartialChain: A certificate chain could not be built to a trusted root authority.
RevocationStatusUnknown: The revocation function was unable to check revocation for the certificate.
OfflineRevocation: The revocation function was unable to check revocation because the revocation server was offline.
ULS Viewer shows the same errors and Health Analyzer shows nothing related:
Cause
Server failed to reboot correctly:
Also the reported certificate's thumbprint was not found in any of the certs in the cert chain on the server: