How to set up "Metadata URL exchange" for my ADFS server


hi everyone,

hope of doing great here... , hope can me on this...this new me.

ok...long story..but brief...i setup adfs server in subnet has following scenario:

- needs go thru 2 layers of firewalls internet. 1 layer used isolate subnet other subnets - advanced security purpose., while layer secure corporate network.

- allows outbound traffic while inbounds explicitly blocked.

- firewall subnet attached not have public interfaces or nat performed.

so now... adfs server, cannot setup 3rd party certificate because of nat issue (there may way set on firewall still doing some  research on that). therefore, told me that... can "metadata url exchange". following comment:

################

what have been doing metadata url exchange needs happen on internet, host file on dmz facing web server instead of on adfs server.  way can keep adfs server still in inside pd network , still able make federation work.

################

so ask complete task? meant...what steps need setup "metadata url exchange".

thank help!

takami chiro

hi takami,

i don’t quite understand “metadata url exchange” part, talking creating relying party trust using federation metadata?

create relying party trust using federation metadata

http://technet.microsoft.com/en-us/library/dd807132.aspx

so now... adfs server, cannot setup 3rd party certificate because of nat issue

if want download third party certificate, have make machine connect internet, or download certificate computer able connect internet import local machine.

you can use own certificate setting internal certification authority within enterprise.

here paragraph quoted article below:

you save on cost of 3rd party certificate using internal pki-issued certificate or self-signed certificate. if choose use internal pki, federation servers, rp federation servers , rp applications must trust pki root. if choose use self-signed certificate, federation servers , resource partner federation servers must import self-signed certificate trusted root certification authorities store in order trust self-signed certificate.

ad fs 2.0: how replace ssl, service communications, token-signing, , token-decrypting certificates

http://social.technet.microsoft.com/wiki/contents/articles/2554.ad-fs-2-0-how-to-replace-the-ssl-service-communications-token-signing-and-token-decrypting-certificates.aspx

best regards,

amy



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL