Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Customer experience | Sales, Customer Insights,...
Unanswered

Old Dynamics Server, Certificate is Expiring on 8/8/2022

(0) ShareShare
ReportReport
Posted on by 5

We used to have support on an old Dynamics On Prem CRM and we no longer have that support.  Attempts to get support has been tricky because the solution was customized and their are fears upgrading will break the system.  In the mean time, We have been delving into articles, blogs, knowledge bases and everything we can find to try and update this expiring certificate.  All attempts have failed miserably.

None of us are very knowledgeable about CRM and it's inner workings.  We relied heavily on the consultants/support team for the behind the scenes operations.

Hoping someone in the forum will at a minimum provide a little guidance or at least help us determine if we should be in a full panic or we can survive.

From what I can tell, there are two servers that appear to be communicating/syncing.  Both utilizing ADFS, Dynamics and IIS.  One of the servers has a beginning address of STS and appears to process authentication before transferring to CRM address on the second server.

Prior to cert expiring, like 30 days prior, we started to experience issues.  Pool would stop and need to be started. Refresh thumbprint.  I was able to keep it running up to now.  So concerned about when the cert officially expires.  These leads to the main question.

When the cert expires, will CRM fail OR will it just prompt users the site is unsecure but they can still use the site?

This will tell me if I am screwed or still have some time.

I am familiar with SSL's and IIS in general but the combination of ADFS and Dynamics is foreign to me.  The articles I am reading make logic sense but I am not sure exactly why we have all these steps and how the interact.  Also, how the servers interact.  None of the articles I have found cover the two server concept.  They all have been geared toward a single server.

Does anyone have a suggestion of sources similar to this two server solution?
How the certs work?  Assume I need two CSRs.  One for each server but how do they align between the servers or do they need to.
Do I need to do one server before another (order of operations)?

What we did up to this point:

I was able to finally get a cert and apply it to the Server running CRM.  After much trial and error, it was loading and showing the correct cert.  We noticed the STS site was displaying the old Cert and found that server.  After it was rebooted, the authentication site (STS) stopped working.  We tried tried applying the cert from the CRM server and failed as expected.  Got a new cert and applied.  The setup of this second server is not the same as the first.  The ADFS and the Federate Meta is different.  Whatever is driving the STS website is also different.  So the steps we saw do not fully apply to this second server.  We ended up rolling back both servers to snapshots and had to reboot them to get the site back up.

Any advice would be very appreciated.

  • DMoody007 Profile Picture
    5 on at
    RE: Old Dynamics Server, Certificate is Expiring on 8/8/2022

    Hello,

    We worked this morning but as soon as 9:00am came. The entire site is down.

    Yes, the cert is a wildcard.

    We got the new cert accepted on the CRM server but could not get it to work on the Auth/STS server.

    That server was configured differently and we did not have the same options we had on the CRM.  It would not let us do some of the steps and keep telling us the Federated Meta data could not be found to update.  Some steps would show the cert but others would not.

    I am presently engaging a consultant I found online.  Hoping they can assist since we are down at the moment.

    Thanks.

  • MLarsen Profile Picture
    488 on at
    RE: Old Dynamics Server, Certificate is Expiring on 8/8/2022

    Have you tried to update the Relying Party Trust on the ADFS server, against the Dynamics 365 server?

    Have you tried to run the IFD and Claim Based Authentication wizard on the Dynamics 365 server again, after you updated the certificate?

    You changed the certificate in IIS on the Dynamics 365 server? Is this a wildcard certificate or specific to the DNS you are using for your setup?

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

🌸 Community Spring Festival 2025 Challenge Winners! 🌸

Congratulations to all our community participants!

Adis Hodzic – Community Spotlight

We are honored to recognize Adis Hodzic as our May 2025 Community…

Kudos to the April Top 10 Community Stars!

Thanks for all your good work in the Community!

Leaderboard > Customer experience | Sales, Customer Insights, CRM

#1
Daivat Vartak (v-9davar) Profile Picture

Daivat Vartak (v-9d... 225 Super User 2025 Season 1

#2
Vahid Ghafarpour Profile Picture

Vahid Ghafarpour 78 Super User 2025 Season 1

#3
Sahra Profile Picture

Sahra 43

Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans