Getting an error when browsing the ADFS Xml

System: Dynamics 365 | Windows 2012 R2

I configured ADFS 3.0 and I am working on the Claim-Based Authentication,  I am getting the error below when browsing the ADFS Xml:

https://adfs.wwmh.net/federationmetadata/2007-06/federationmetadata.xml
There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.


I restarted the CRM server and the ADFS service but it still shows the error.  I am working on using PowerShell but cant find the ADFS 3.0 snap-in on the CRM server
LVL 1
apollo7Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

carlos sotoIT AdministratorCommented:
hi

do you have a specifik service account that is running the ADFS service? if so, check if it has the permissions to read the certificate properties
0
apollo7Author Commented:
Using  the CRM Admin account, the System Admin told me it has active directory rights, what do I look at to see if it has permissions to read the certificate properties?
0
carlos sotoIT AdministratorCommented:
open computer certificates in mmc.exe. Go to personal certificates, right click your certificate and select "all tasks" and "manage private keys"
check that adfssrv has read rights. Add the account that is running the ADFS Service, and then give the account at least read permissions.

Also, the url you poster https://adfs.wwmh.net/federationmetadata/2007-06/federationmetadata.xml isnt working. Maybe its only open from the inside?? otherwise i should be able to download the xml file or get the same error as you
0
Introducing the "443 Security Simplified" Podcast

This new podcast puts you inside the minds of leading white-hat hackers and security researchers. Hosts Marc Laliberte and Corey Nachreiner turn complex security concepts into easily understood and actionable insights on the latest cyber security headlines and trends.

apollo7Author Commented:
When I open computer certificates in mmc.exe and go to personal certificates, I right click one of the two certificates and select "all tasks" but don't get "manage private keys" - I get "manage enrollment policies"

ADFS
I checked that adfssrv has read rights. I gave the adfssrv all rights except full control

I am  not getting the option to add the account that is running the ADFS Service and give the account at least read permissions.
0
carlos sotoIT AdministratorCommented:
look at the certificates for the computer, not current user. And check for the permissions there.

certificate store
You should be able to add a user to the certificate, the same way as you add permissions to a folder

was the adfs url you posted the right url? is it open from the outside?
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
apollo7Author Commented:
I was able to finish the adfs setup by having the System Admin do the following:

Created a user: adfs18 and assigned that to run the adfs service. He also added a DNS entry that points adfs.wwmh.net to the CRMTEST

I can now browse the adfs xml, problem solved!

Thanks
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Powershell

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.