Solved

token signing and decrypting cert will expire on ADFS servers Exchange 2010 hybrid organization

Posted on 2015-02-04
2
225 Views
Last Modified: 2015-02-04
Hello Experts,

As per file attached, I have a client that has the following infrastructure:

2 MBX Exchange servers in a DAG[Exchange 2010 SP3]

2 CAS/HUB servers

2 ADFS servers with WNLB[Windows 2008 R2 multicast converged nodes]

1 ADFS proxy server  [Windows 2008 R2]

Exchange 2010 hybrid with office 365. One send connector to office 365 and one send connector to route outbound email issues through spam symantec gateway

Issue:

Both token signing and decrypting certs will expire soon. please respond following questions:

Will my systems be affected once the certs are expired on the ADFS servers? i.e, email systems, ADFS, and so on? Please describe service impact

If so,

Please, describe how and why my systems will be affected.

How can we renew this certs, step by step, using powershell or GUI

Do we have to renew certs individually on each ADFS servers?

Do we have to export/import the new certs onto any other servers?

Please advise
0
Comment
Question by:Jerry Seinfield
2 Comments
 
LVL 40

Accepted Solution

by:
Vasil Michev (MVP) earned 250 total points
ID: 40588750
You need to renew the cert, otherwise AD FS will stop working, and any services dependent on AD FS for auth as well.

Follow the steps in these articles to replace the token certs:
3.0: http://blogs.technet.com/b/tune_in_to_windows_intune/archive/2013/11/13/replace-certificates-on-adfs-3-0.aspx
2.0/2.1: http://social.technet.microsoft.com/wiki/contents/articles/2554.ad-fs-2-0-how-to-replace-the-ssl-service-communications-token-signing-and-token-decrypting-certificates.aspx
0
 
LVL 16

Assisted Solution

by:Ivan
Ivan earned 250 total points
ID: 40588881
Hi,

if those certificates are self signed, which is default, then they will auto-renew them self, 20 days before expiration.
Usually only service communications certificate is some public cert.

You should check if auto-renewal is on, but that is by default as well.

Add-PSSnapin Microsoft.Adfs.Powershell

Get-ADFSProperties  

something like this Is a command to check it.

Regards,
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
JRNL_WRAP_ERROR issue in sysvol 20 34
outlook 6 42
Outlook 2013 License Question 8 30
Forcing domain PC to ignore redirected folders on 2012 domain network 11 24
This article runs through the process of deploying a single EXE application selectively to a group of user.
Adoption of Microsoft’s Enterprise Mobility and Security solution and Office 365 will re-order the File Sync and Share market Microsoft has stated that its Enterprise Mobility + Security (EMS) is the fastest growing product in the history of the …
In a previous video Micro Tutorial here at Experts Exchange (http://www.experts-exchange.com/videos/1358/How-to-get-a-free-trial-of-Office-365-with-the-Office-2016-desktop-applications.html), I explained how to get a free, one-month trial of Office …
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question