ADFS Token and Signing cert renewal

dimago 41 Reputation points
2020-08-20T02:16:42.143+00:00

Hello guys!

I'm doing my first cycle of token certs renewal. At this moment I have 2 for both, Primary and Secondary. Everything seems to be just fine.

I'm trying to be ahead of the game and tried to replace the RP configuration in advance. I did it for my first RP and replaced the old cert with the new one (signing) and everything worked just fine! Hell yeah, so easy!!!

So I decided to move to the second RP and for my surprise it did not work. So I tried one more RP and same thing! I did the forth and omg same thing.

So now I'm confuse but I did some research and looks like the RP must have be able to "read/understand/work" with those 2 certs, Primary and Secondary. Is this really the case?

I have about 10 RP/applications and 1 I need the vendor to perform the change. Some I can do it on the Operating System (Linux) changing the config file and some others I really need to access the UI and change it over there, of course authenticated. So 9 are on premises and 1 is like a SaaS.

That said, how am I supposed to perform this configuration/rollout?

If the cert expires, I will not be able to login on the application/RP to change the configuration to the newer cert.

Please, some advise, guidance, lesson learned is very welcome!

Thanks!

Microsoft Security | Active Directory Federation Services
{count} votes

1 answer

Sort by: Most helpful
  1. Mark Morowczynski 251 Reputation points Microsoft Employee
    2023-01-22T15:26:01.0333333+00:00

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.