web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Customer experience | Sales, Customer Insights,...
Suggested answer

ADFS 2.0 SSL Certificate Renewal

(0) ShareShare
ReportReport
Posted on by 15

Hi all, new poster looking for some support. I'm relatively new to ADFS, our last admin is unavailable at the moment, so I'm looking for some help please!

My ADFS SSL Certificate expires in 5 days. I've renewed the certificate & installed on my ADFS Server (ADFS 2.0 Windows Server 2008 R2 - yes I know, it's soon to be removed from our estate!)

  • Steps Taken so far;Installed new certificate from CA on the ADFS Server

  • In ADFS 2.0 Management I've generated new Token Signing & Token Decrypting Certs & set these both as primary. I've also added the new cert for "Service Communications"

  • I've then opened up IIS Manager on the ADFS Server & changed the default site binding to use the new cert, then done an IIS Reset.


At this stage, I had no access to CRM on the web. So I went over to the CRM Application server & went through the Claims Based Authentication & IFD Configuration pages, accepting the already set defaults as per this guide I found - tisski.com/.../

This then restored CRM access, great!

Only, when inspecting the certificate being used for IFD & CBA, I see it's still using the old cert that's due to expire in 5 days. Not good! So I then;

  • Installed the new PFX Cert from the ADFS server on the CRM App Server. This cert now shows in MMC on the app server under Personal (along with the old one)

Now, when I try to switch over to the new certificate for CBA & IFD, I get the error "The encryption certificate 'CN=*.xxx, O=xxx, L=xxx, S=xxx, C=GB' does not exist in the local computer certificate store"

Any ideas what I'm missing here?

Thanks in advance, hopefully I've been clear in my description of what's happened so far!

I have the same question (0)
  • Hugo Serras Profile Picture
    on at
    RE: ADFS 2.0 SSL Certificate Renewal

    Great news

  • Dynamics2016_Admin Profile Picture
    15 on at
    RE: ADFS 2.0 SSL Certificate Renewal

    Quick update, I’ve just realised I forgot to delete the old certificate from the CRM application server!

    Deleted this, updated the relying parties, IIS reset & it’s back up and running.

    Thanks for taking the time to assist!

  • Suggested answer
    Hugo Serras Profile Picture
    on at
    RE: ADFS 2.0 SSL Certificate Renewal

    Well, in that case, I advise you to open a support case with Microsoft, since it may be needed more troubleshooting

  • Dynamics2016_Admin Profile Picture
    15 on at
    RE: ADFS 2.0 SSL Certificate Renewal

    Thanks Hugo, the 2 relying party trusts have yellow exclamation marks. When I select update, the error is "an error occurred during the attempt to read the federation metadata. Verify the specified URL or host name is a valid federation metadata endpoint"

    I'm fortunate that I use VMware & have a snapshot of the ADFS server pre any changes I made today, so I can roll back in theory.

    I do need to get it resolved before Friday though.

  • Hugo Serras Profile Picture
    on at
    RE: ADFS 2.0 SSL Certificate Renewal

    If you go to ADFS -> Trust Relationships -> Relying party trusts, you have the Claims RPT and IFD RPT. If you have a red cross in them, you can update the federation metadata by right clicking them

  • Dynamics2016_Admin Profile Picture
    15 on at
    RE: ADFS 2.0 SSL Certificate Renewal

    Hi Hugo,

    Sorry, new to ADFS, I can see they relying party trusts on the ADFS Server, what is it I'm actually have to update?

  • Suggested answer
    Hugo Serras Profile Picture
    on at
    RE: ADFS 2.0 SSL Certificate Renewal

    Hello,

    Have you updated your relying party trusts federation metadata in ADFS server?

    When you added the certificate, you added in the computer store and not your user?

    Best regards

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Andrés Arias – Community Spotlight

We are honored to recognize Andrés Arias as our Community Spotlight honoree for…

Leaderboard > Customer experience | Sales, Customer Insights, CRM

#1
DAnny3211 Profile Picture

DAnny3211 134

#2
Daniyal Khaleel Profile Picture

Daniyal Khaleel 106

#3
Abhilash Warrier Profile Picture

Abhilash Warrier 70 Super User 2025 Season 2

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans