We have workshops to help move off ADFS https://techcommunity.microsoft.com/t5/community-events-list/microsoft-workshops-how-to-successfully-migrate-away-from-ad-fs/m-p/3668480 & https://www.microsoft.com/en-us/security/business/identity-access/upgrade-adfs
ADFS Token and Signing cert renewal
Hello guys!
I'm doing my first cycle of token certs renewal. At this moment I have 2 for both, Primary and Secondary. Everything seems to be just fine.
I'm trying to be ahead of the game and tried to replace the RP configuration in advance. I did it for my first RP and replaced the old cert with the new one (signing) and everything worked just fine! Hell yeah, so easy!!!
So I decided to move to the second RP and for my surprise it did not work. So I tried one more RP and same thing! I did the forth and omg same thing.
So now I'm confuse but I did some research and looks like the RP must have be able to "read/understand/work" with those 2 certs, Primary and Secondary. Is this really the case?
I have about 10 RP/applications and 1 I need the vendor to perform the change. Some I can do it on the Operating System (Linux) changing the config file and some others I really need to access the UI and change it over there, of course authenticated. So 9 are on premises and 1 is like a SaaS.
That said, how am I supposed to perform this configuration/rollout?
If the cert expires, I will not be able to login on the application/RP to change the configuration to the newer cert.
Please, some advise, guidance, lesson learned is very welcome!
Thanks!
Microsoft Security | Active Directory Federation Services
1 answer
Sort by: Most helpful
-
Mark Morowczynski 251 Reputation points Microsoft Employee2023-01-22T15:26:01.0333333+00:00