PartialChain: A certificate chain could not be built to a trusted root authority.

Applies to SharePoint 2016; not tested on other versions of SharePoint.  

Symptoms

 

Windows Application Event Viewer shows two certificate-related errors every minute as follows:

 

Event ID 8306

 

An exception occurred when trying to issue security token: ID3242: The security token could not be authenticated or authorized..

 

Event ID 8311

 

An operation failed because the following certificate has validation errors:

 

Subject Name: CN=SharePoint Security Token Service, OU=SharePoint, O=Microsoft, C=US

Issuer Name: CN=SharePoint Root Authority, OU=SharePoint, O=Microsoft, C=US

Thumbprint: 8C0669A6945F6A310538F1F8159D541CBDFE9427

 

Errors:

 

PartialChain: A certificate chain could not be built to a trusted root authority.

RevocationStatusUnknown: The revocation function was unable to check revocation for the certificate.

OfflineRevocation: The revocation function was unable to check revocation because the revocation server was offline.

 

Graphical user interface, text, application, email

Description automatically generated

 

ULS Viewer shows the same errors and Health Analyzer shows nothing related:


Cause

 

Server failed to reboot correctly:

Also the reported certificate's thumbprint was not found in any of the certs in the cert chain on the server:


Resolution

 

Run IISRESET. Restarting the SharePoint Web Services site in IIS did not stop the error, but IISRESET did.


Popular posts from this blog

October 2025 SharePoint CU Failed to Install After Applying September 2025 SharePoint CU

September 2025 SharePoint 2016 CU - Configuration Wizard failed

Broken Site Collection