web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Small and medium business | Business Central, N...
Suggested Answer

ADFS 2.0 - Certificate Renewal Help

(0) ShareShare
ReportReport
Posted on by 15

Hi all, new poster looking for some support. I'm relatively new to ADFS, our last admin is unavailable at the moment, so I'm looking for some help please!

My ADFS SSL Certificate expires in 5 days. I've renewed the certificate & installed on my ADFS Server (ADFS 2.0 Windows Server 2008 R2 - yes I know, it's soon to be removed from our estate!)

Steps Taken so far;

  1. Installed new certificate from CA on the ADFS Server
  2. In ADFS 2.0 Management I've generated new Token Signing & Token Decrypting Certs & set these both as primary. I've also added the new cert for "Service Communications"
  3. I've then opened up IIS Manager on the ADFS Server & changed the default site binding to use the new cert, then done an IIS Reset. 

At this stage, I had no access to CRM on the web. So I went over to the CRM Application server & went through the Claims Based Authentication & IFD Configuration pages, accepting the already set defaults as per this guide I found - https://tisski.com/expiring-adfs-certificates/

This then restored CRM access, great!

Only, when inspecting the certificate being used for IFD & CBA, I see it's still using the old cert that's due to expire in 5 days. Not good! So I then;

  1. Installed the new PFX Cert from the ADFS server on the CRM App Server. This cert now shows in MMC on the app server under Personal (along with the old one)

Now, when I try to switch over to the new certificate for CBA & IFD, I get the error "The encryption certificate 'CN=*.xxx, O=xxx, L=xxx, S=xxx, C=GB' does not exist in the local computer certificate store"

Any ideas what I'm missing here? 

Thanks in advance, hopefully I've been clear in my description of what's happened so far!

I have the same question (0)
  • Suggested answer
    Marco Mels Profile Picture
    on at

    Hello,

    This is a Dynamics 365 Business Central forum, but with ADFS / SSL in Dynamics 365 BC, the old SSL may be cached and the only way for us to also work with the new SSL cert is to disable SSL completely, restart, enable SSL again. At that point, the new cert is taken into production.

    Maybe something similar does exist as a solution for the app you are working with. Best however it to raise this request in the correct forum.

    Please verify the answer if the above is already sufficient.

    Thanks.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > Small and medium business | Business Central, NAV, RMS

#1
OussamaSabbouh Profile Picture

OussamaSabbouh 2,066

#2
YUN ZHU Profile Picture

YUN ZHU 658 Super User 2025 Season 2

#3
Sumit Singh Profile Picture

Sumit Singh 595

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans