How to set up "Metadata URL exchange" for my ADFS server
hi everyone,
hope of doing great here... , hope can me on this...this new me.
ok...long story..but brief...i setup adfs server in subnet has following scenario:
- needs go thru 2 layers of firewalls internet. 1 layer used isolate subnet other subnets - advanced security purpose., while layer secure corporate network.
- allows outbound traffic while inbounds explicitly blocked.
- firewall subnet attached not have public interfaces or nat performed.
so now... adfs server, cannot setup 3rd party certificate because of nat issue (there may way set on firewall still doing some research on that). therefore, told me that... can "metadata url exchange". following comment:
################
what have been doing metadata url exchange needs happen on internet, host file on dmz facing web server instead of on adfs server. way can keep adfs server still in inside pd network , still able make federation work.
################
so ask complete task? meant...what steps need setup "metadata url exchange".
thank help!
takami chiro
hi takami,
i don’t quite understand “metadata url exchange” part, talking creating relying party trust using federation metadata?
create relying party trust using federation metadata
http://technet.microsoft.com/en-us/library/dd807132.aspx
so now... adfs server, cannot setup 3rd party certificate because of nat issue
if want download third party certificate, have make machine connect internet, or download certificate computer able connect internet import local machine.
you can use own certificate setting internal certification authority within enterprise.
here paragraph quoted article below:
you save on cost of 3rd party certificate using internal pki-issued certificate or self-signed certificate. if choose use internal pki, federation servers, rp federation servers , rp applications must trust pki root. if choose use self-signed certificate, federation servers , resource partner federation servers must import self-signed certificate trusted root certification authorities store in order trust self-signed certificate.
ad fs 2.0: how replace ssl, service communications, token-signing, , token-decrypting certificates
best regards,
amy
Windows Server > Directory Services
Comments
Post a Comment