Creating a self signed certificate to configure ADFS

Posted on 2014-10-14
Last Modified: 2014-10-17
Hello Everyone,
I am trying to setup ADFS. In the setup it asks for a certificate, I think I therefore need to create a self signed certificate.

Not too big on certs, tried playing around but couldn't figure it out.

Certificate will sit on server named "SCSM-ADFS" purposed for an ADFS designed portal that will be on an extranet to be accessed by clients.

Created another server on domain with certificate authority services and IIS to aid with cert creation - not sure if this was useful or not.

Certificate needs to be able to export as a PFX due to ADFS setup requirement.

Thanks in advance
Question by:Sir Learnalot
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 29

Expert Comment

ID: 40380243
Certificate will sit on server named "SCSM-ADFS" purposed for an ADFS designed portal that will be on an extranet to be accessed by clients.

I would suggest in this instance you acquire a third party certificate.
Simply get one a go-daddy or rapid ssl etc.

You can then export to pfx for future use as needed.

To create a Self-signed cert:

Open IIS Manager and navigate to the level you want to manage.
In Features view, double-click Server Certificates.
In the Actions pane, click Create Self-Signed Certificate.
On the Create Self-Signed Certificate page, type a friendly name for the certificate in the Specify a friendly name for the certificate box, and then click OK.

Author Comment

by:Sir Learnalot
ID: 40380627
At the moment I am performing a test dev deployment, so a publicly signed cert wouldn't be necessary until I deploy in production...

Creating a self-signed certificate through IIS is not sufficient for 2 reasons:

1) IIS is installed on a different machine, although on the same domain this means generating a self-signed cert on the IIS machine will produce a diff. certificate than the one needed on the ADFS server

2) The certificate is too basic and lacks Subject Name, alternative DNS values, e.t.c.
LVL 29

Expert Comment

ID: 40380654
Knowing the requirement as far as SAN etc would have been helpful initially.

Here is a step by step on creating a selfsigned SAN certificate using openssl:
Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.


Author Comment

by:Sir Learnalot
ID: 40380668
Sorry for not listing that initially, I am new to certs like I said and have not yet wrapped my head around them. Do you have any methods for creating one through a windows server? This way I can avoid working with OpenSSL and having to learn something else new entirely... Thanks in advance.
LVL 29

Accepted Solution

becraig earned 500 total points
ID: 40380696
Here is an untested powershell script which might do this for you:

Due to the SAN requirement we cannot use makecert, hopefully the script at the location above might be easy get working.

Author Closing Comment

by:Sir Learnalot
ID: 40387363
Thank you for your feedback, I assigned you points for your effort. However I ended up solving this differently. I used and it did all the work for me :)

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

689 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question