web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Microsoft Dynamics CRM (Archived)

Issue with updating certificate

(0) ShareShare
ReportReport
Posted on by

A UCC cert expired today causing some issues, including CRM and ADFS. A renewed cert was imported to my CRM 2011 server and I've gone through to try and update CRM and ADFS but I'm still having issues.

CRM 2011 and ADFS 2.0 are on the same server.

Here's what I've done:

  1. Added the new cert to Local Computer of the CRM / ADFS server in the Personal and Trusted Root stores
  2. Granted ADFS and CRM app pool account read permissions to the new cert
  3. Updated CRM and ADFS IIS site bindings for the new cert

At this point I've tried to reconfigure Claims Based Auth in Deployment Manager which fails - I leave the federation metadata URL unchanged and select the new cert.

System checks complains that the federation metadata URL is not available and the encryption certificate doe not exist in the local computer store.

My CRM site results in this error - Relying Party Certificate was not found

I've gone into ADFS 2.0 and set the Service Communications certificate to the new cert and when I review the Relying Party Trusts for my internal and external identifiers they read certificate has expired on the encryption tab and show the details of the expired cert. Trying to update the two trusts from Federation Metadata throws a 502 error: bad gateway.

Any ideas on what I'm missing to get the certs updated and the site restored?

Thanks All

*This post is locked for comments

I have the same question (0)
  • Ragnar Hilmarsson Profile Picture
    3,427 on at

    hi

    my sugges is try to uninstall ADFS and install again and besure when configure to delete existing database.

    It sound like some cache in metadata in ADFS

  • Mohammad Atif Profile Picture
    on at

    Try to browse https://localhost/adfs/ls/IdpInitiatedSignOn.aspx from your ADFS server, and if you are unable to access the ADFS Page then you are to go for uninstallation and reinstallation of ADFS database

    Regards,

    Mohammad

  • Community Member Profile Picture
    on at

    I can access that page and I get the credentials popup, but it doesn't authenticate.

  • Verified answer
    Community Member Profile Picture
    on at

    Issue has been resolved - there was a proxy settings that was blocking my relying party trusts and blocking Deployment Managed from connecting to the ADFS metadata URL.

  • JoJi Profile Picture
    250 on at

    Can you please tell me where exactly you did the proxy setting an what was that?

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > 🔒一 Microsoft Dynamics CRM (Archived)

#1
SA-08121319-0 Profile Picture

SA-08121319-0 4

#1
Calum MacFarlane Profile Picture

Calum MacFarlane 4

#3
Alex Fun Wei Jie Profile Picture

Alex Fun Wei Jie 2

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans