Ok got it.
And yeah we check the issue stricly since that is a problem for all different kind of things.
To think a little out of the box... you could steer zitadel to you backend "faking" the dns name from the target adfs by setting this in the containers dns section.
This way the issuer error might go away. Otherwise you might want to remove your backend.
I will send you a link for a quick chat about this.