Solved

token signing and decrypting cert will expire on ADFS servers Exchange 2010 hybrid organization

Posted on 2015-02-04
2
224 Views
Last Modified: 2015-02-04
Hello Experts,

As per file attached, I have a client that has the following infrastructure:

2 MBX Exchange servers in a DAG[Exchange 2010 SP3]

2 CAS/HUB servers

2 ADFS servers with WNLB[Windows 2008 R2 multicast converged nodes]

1 ADFS proxy server  [Windows 2008 R2]

Exchange 2010 hybrid with office 365. One send connector to office 365 and one send connector to route outbound email issues through spam symantec gateway

Issue:

Both token signing and decrypting certs will expire soon. please respond following questions:

Will my systems be affected once the certs are expired on the ADFS servers? i.e, email systems, ADFS, and so on? Please describe service impact

If so,

Please, describe how and why my systems will be affected.

How can we renew this certs, step by step, using powershell or GUI

Do we have to renew certs individually on each ADFS servers?

Do we have to export/import the new certs onto any other servers?

Please advise
0
Comment
Question by:Jerry Seinfield
2 Comments
 
LVL 39

Accepted Solution

by:
Vasil Michev (MVP) earned 250 total points
ID: 40588750
You need to renew the cert, otherwise AD FS will stop working, and any services dependent on AD FS for auth as well.

Follow the steps in these articles to replace the token certs:
3.0: http://blogs.technet.com/b/tune_in_to_windows_intune/archive/2013/11/13/replace-certificates-on-adfs-3-0.aspx
2.0/2.1: http://social.technet.microsoft.com/wiki/contents/articles/2554.ad-fs-2-0-how-to-replace-the-ssl-service-communications-token-signing-and-token-decrypting-certificates.aspx
0
 
LVL 16

Assisted Solution

by:Ivan
Ivan earned 250 total points
ID: 40588881
Hi,

if those certificates are self signed, which is default, then they will auto-renew them self, 20 days before expiration.
Usually only service communications certificate is some public cert.

You should check if auto-renewal is on, but that is by default as well.

Add-PSSnapin Microsoft.Adfs.Powershell

Get-ADFSProperties  

something like this Is a command to check it.

Regards,
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This is my first article on Expert Exchange on the Manual Method of Exporting Office 365 Mailboxes to PST format by using the eDiscovery mechanism of Office. Hope you will enjoy the article.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
In a previous video Micro Tutorial here at Experts Exchange (http://www.experts-exchange.com/videos/1358/How-to-get-a-free-trial-of-Office-365-with-the-Office-2016-desktop-applications.html), I explained how to get a free, one-month trial of Office …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

27 Experts available now in Live!

Get 1:1 Help Now