web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Microsoft Dynamics CRM (Archived)

What we learned: Renewing or Replace a SSL Certificate in CRM

(5) ShareShare
ReportReport
Posted on by 130

Instead of a question, I'm posting a process that worked for us.

Facing an SSL certificate expiration date, we learned the hard way that updating an SSL cert in an CRM environment is trickier than first thought.  In hopes that someone else can learn from our exasperation, I'm posting the process we used to update a new SSL cert to replace an expiring cert.

1.  Remove (delete) the old cert using MMC on the CRM web servers & ADFS servers.  Verify removal of the cert by reviewing your  IIS https bindings.  We found that if we did not remove the old one first, application of the new one would not work.

2. Add the new cert to the ADFS server first.  Import new cert into MMC cert snapins console. Be sure your 'AppPool user account' has read permissions. You also need to be sure that the 'ADFS service user account' has full permissions to the cert.  Bind new cert to https in IIS.  From your cmd line, perform an IISreset.

3. Add the new cert to your CRM web application servers...all of them if there's more than one.  Import new cert into MMC cert snapins console. Be sure your 'AppPool user account' has read permissions. Bind new cert to https in IIS.  From your cmd line, perform an IISreset.

4.  On your ADFS server, update the cert in ADFS Mgmt Console.  Under Service > certificates > Set service communications certificate to new cert.

5. Back again to your CRM web servers, fire up the 'Configure Claims Wizard', update to the new certificate, and apply.

6. On the ADFS server, in the ADFS Mgmt Console, under 'Trust Relationships', update relying trust federation metadata for all instances.

7.  Test CRM...this worked for us.

 

Happy CRM'ing,

Marilyn Sizemore

 

*This post is locked for comments

I have the same question (0)
  • Suggested answer
    marsizemore Profile Picture
    130 on at
    Re: What we learned: Renewing or Replace a SSL Certificate in CRM

    No answer required, however proactive community input is always appreciated.  -MCS

  • Community Member Profile Picture
    on at
    RE: What we learned: Renewing or Replace a SSL Certificate in CRM

    Good write up!

    We had this problem today. It's surprising just how many places you need to check the certificate and we found about 3 expired certificates still existed. In version 2.0 of ADFS you need to update the certificate in the binding for the ADFS website in IIS on the ADFS server too. This is no longer required in newer versions.

  • Integration Profile Picture
    651 on at
    RE: What we learned: Renewing or Replace a SSL Certificate in CRM

    HI Marilyn ,

    I have similar question.We are using CRM 2016 on premise with three tier architecture.

    1.CRM app server

    2.CRM integration server

    3.CRM DB server.

    We are not using ADFS and Claims based authentication is disabled in our APP server.So still the same above mentioned steps will help us to replace the certificate?Please.

  • Rahul Patil Profile Picture
    5 on at
    RE: What we learned: Renewing or Replace a SSL Certificate in CRM

    Thank you for sharing, we also learned the hard way

  • Suggested answer
    indlad Profile Picture
    450 on at
    RE: What we learned: Renewing or Replace a SSL Certificate in CRM

    Thank you Marilyn, I was looking for these steps for our SSL renewal.

  • indlad Profile Picture
    450 on at
    RE: What we learned: Renewing or Replace a SSL Certificate in CRM

    Hi Marilyn,

             In our environments unfortunately our security team renewed the SSL cert on CRM front end and Load Balencer and that broke our Dynamics 365 App for Outlook. We have put the certificate back but the app failed to connect. Everything else working fine and users can access CRM. I think only OAuth2 is failing. we have DEV, TEST, UAT and PROD and all have the same ADFS Sever and use the same wild card certificate. Logically thinking something on the ADFS Side got updated. We refreshed Relying Party trust on the ADFS Server but still we have this issue. Appreciate your help/pointer to this issue.

    Thank you

    Dan,

  • Community Member Profile Picture
    on at
    RE: What we learned: Renewing or Replace a SSL Certificate in CRM

    Thanks, this was a great help!!

  • Phil.Arnold1981 Profile Picture
    15 on at
    RE: What we learned: Renewing or Replace a SSL Certificate in CRM

    we found that following the certificate renewal we had to re-enable oAuth!

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Abhilash Warrier – Community Spotlight

We are honored to recognize Abhilash Warrier as our Community Spotlight honoree for…

Leaderboard > 🔒一 Microsoft Dynamics CRM (Archived)

#1
Community Member Profile Picture

Community Member 2

#1
HR-09070029-0 Profile Picture

HR-09070029-0 2

#1
UllrSki Profile Picture

UllrSki 2

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans