ADFS setup with multiple domains. Certificate and A records requirements for multiple domains.

Hello,
I just wanted to verify if you need to use several UPNs and federate several domains with one ADFS server for Office 365, do you need an additional names for each on the cert as well as A record in external DNS to point to ADFS proxy?

I am reading that you only need one A record to point to the FQDN of your ADFS farm and just one name on the cert? Correct?

Also, on the cert, does the FQDN of the server farm needs to be common name or it can just be alternative name? So, if this can be an alternative name, then we can use the UCC cert, for example, from the Hybrid server, and just add adfs.domain.com as an alternative name? What is the best practice? Is it best to buy a separate certificate for ADFS server with common name as adfs.domain.com?

Please, advice.
Thank you very much.
claudiamcseAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Vasil Michev (MVP)Commented:
The subject name should point to the FQDN, if you only have the FQDN added to the SAN it might not work: http://technet.microsoft.com/en-us/library/hh341473.aspx

You do not need certificates for other domains, only for the AD FS endpoint. The recommended setup is to create the DNS record sts.domain.com, select the  endpoint sts.domain.com during AD FS setup and select the corresponding SSL certificate with sts.domain.com subject name. The names of course can be different, just make sure all these three pieces match.

You do not need separate certificates for subdomains as well.

Here is also another thread on the community forums that discusses this, and it might help with the other issue you are facing:

http://community.office365.com/en-us/forums/613/p/43477/149671.aspx
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Jeffrey Kane - TechSoEasyPrincipal ConsultantCommented:
You'll find all of your answers here:
http://community.office365.com/en-us/forums/613/t/195339.aspx

(and perhaps answers to a few things you haven't asked yet)  :-)
0
claudiamcseAuthor Commented:
Thank you very much! Excellent.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Office 365

From novice to tech pro — start learning today.