Creating a self signed certificate to configure ADFS

Posted on 2014-10-14
Last Modified: 2014-10-17
Hello Everyone,
I am trying to setup ADFS. In the setup it asks for a certificate, I think I therefore need to create a self signed certificate.

Not too big on certs, tried playing around but couldn't figure it out.

Certificate will sit on server named "SCSM-ADFS" purposed for an ADFS designed portal that will be on an extranet to be accessed by clients.

Created another server on domain with certificate authority services and IIS to aid with cert creation - not sure if this was useful or not.

Certificate needs to be able to export as a PFX due to ADFS setup requirement.

Thanks in advance
Question by:Sir Learnalot
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 29

Expert Comment

ID: 40380243
Certificate will sit on server named "SCSM-ADFS" purposed for an ADFS designed portal that will be on an extranet to be accessed by clients.

I would suggest in this instance you acquire a third party certificate.
Simply get one a go-daddy or rapid ssl etc.

You can then export to pfx for future use as needed.

To create a Self-signed cert:

Open IIS Manager and navigate to the level you want to manage.
In Features view, double-click Server Certificates.
In the Actions pane, click Create Self-Signed Certificate.
On the Create Self-Signed Certificate page, type a friendly name for the certificate in the Specify a friendly name for the certificate box, and then click OK.

Author Comment

by:Sir Learnalot
ID: 40380627
At the moment I am performing a test dev deployment, so a publicly signed cert wouldn't be necessary until I deploy in production...

Creating a self-signed certificate through IIS is not sufficient for 2 reasons:

1) IIS is installed on a different machine, although on the same domain this means generating a self-signed cert on the IIS machine will produce a diff. certificate than the one needed on the ADFS server

2) The certificate is too basic and lacks Subject Name, alternative DNS values, e.t.c.
LVL 29

Expert Comment

ID: 40380654
Knowing the requirement as far as SAN etc would have been helpful initially.

Here is a step by step on creating a selfsigned SAN certificate using openssl:
Space-Age Communications Transitions to DevOps

ViaSat, a global provider of satellite and wireless communications, securely connects businesses, governments, and organizations to the Internet. Learn how ViaSat’s Network Solutions Engineer, drove the transition from a traditional network support to a DevOps-centric model.


Author Comment

by:Sir Learnalot
ID: 40380668
Sorry for not listing that initially, I am new to certs like I said and have not yet wrapped my head around them. Do you have any methods for creating one through a windows server? This way I can avoid working with OpenSSL and having to learn something else new entirely... Thanks in advance.
LVL 29

Accepted Solution

becraig earned 500 total points
ID: 40380696
Here is an untested powershell script which might do this for you:

Due to the SAN requirement we cannot use makecert, hopefully the script at the location above might be easy get working.

Author Closing Comment

by:Sir Learnalot
ID: 40387363
Thank you for your feedback, I assigned you points for your effort. However I ended up solving this differently. I used and it did all the work for me :)

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

A phishing scam that claims a recipient’s credit card details have been “suspended” is the latest trend in spoof emails.
A hard and fast method for reducing Active Directory Administrators members.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question