Solved

Office 365

Posted on 2014-02-18
6
381 Views
Last Modified: 2014-02-23
I have attached the error or alert I receive each time I open the Office 365 portal. How can I renew of fix this issue?
Premises-Error.gif
0
Comment
Question by:TabDB
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 41

Expert Comment

by:Vasil Michev (MVP)
ID: 39868423
As the alert says, one of the certificates you are using with AD FS will expire soon. This might be either the token signing/decrypting certificates or the communication ones. Review the following article for the procedure of changing them:

http://social.technet.microsoft.com/wiki/contents/articles/2554.ad-fs-2-0-how-to-replace-the-ssl-service-communications-token-signing-and-token-decrypting-certificates.aspx

If you are using self-signed certificates for token signing/decrypting, you might want to enable auto-renewal:

http://social.technet.microsoft.com/wiki/contents/articles/1424.ad-fs-2-0-how-to-enable-and-immediately-use-autocertificaterollover.aspx

Lastly, make sure to update the trust settings once you have replaced the certificates:

http://support.microsoft.com/kb/2647048
0
 

Author Comment

by:TabDB
ID: 39870187
It is both the Token Decrypting and the Token Signing. So how do I create new certs? I see how to replace them but I did not build this system so I do not know how to create new ones. Is this performed on a server within my network? They appear to be internal created certs since the Service Communications cert appears to be created by a third party provider.
0
 
LVL 41

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 39870251
Ok, so you are using self-signed ones. You can use PowerShell to renew them:

Add-PSSnapin Microsoft.Adfs.Powershell

Update-ADFSCertificate -CertificateType: Token-Signing -Urgent:$true 

Update-ADFSCertificate -CertificateType: Token-decrypting -Urgent:$true

Update-MSOLFederatedDomain –DomainName <your domainname>

Open in new window


This will potentially cause a downtime for all federated users, so make sure to plan it after working hours.


To avoid this from happening in the future, you might want to enable auto-renewal:

http://social.technet.microsoft.com/wiki/contents/articles/1424.ad-fs-2-0-how-to-enable-and-immediately-use-autocertificaterollover.aspx

And make sure to also check the validity of the communication cert.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:TabDB
ID: 39870270
Very well. Thank You. I will proceed with this on Saturday.
0
 
LVL 41

Expert Comment

by:Vasil Michev (MVP)
ID: 39870293
Oh, and of course make sure you have installed the WAAD PowerShell Module on the AD FS machine:

http://technet.microsoft.com/en-us/library/jj151815.aspx

Here's also another article that covers all the steps in more detail:

http://www.kraak.com/?p=190
0
 

Author Closing Comment

by:TabDB
ID: 39880688
This solved my issue. Only took five minutes. Very much appreciated.
0

Featured Post

[Webinar] How Hackers Steal Your Credentials

Do You Know How Hackers Steal Your Credentials? Join us and Skyport Systems to learn how hackers steal your credentials and why Active Directory must be secure to stop them. Thursday, July 13, 2017 10:00 A.M. PDT

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Read this checklist to learn more about the 15 things you should never include in an email signature.
Cloud-based technologies and services will continue to grow in popularity in 2017 thanks to the simple, scalable and cost-effective solutions they deliver. Here are three areas where cloud adoption is poised to really take off.
Office 365 is currently available in five editions. Three of them are for business use: Office 365 Business Essentials, Office 365 Business, and Office 365 Business Premium. Two of them are for home/personal use: Office 365 Home and Office 365 Perso…
In a previous video Micro Tutorial here at Experts Exchange (http://www.experts-exchange.com/videos/1358/How-to-get-a-free-trial-of-Office-365-with-the-Office-2016-desktop-applications.html), I explained how to get a free, one-month trial of Office …

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question