6.5.3 AD FS
Deploy to every AD FS server and proxy, using an RSA certificate
Use the AD FS template on federation servers and the WAP template on Web Application Proxy servers.
| Template | Install the agent on | What it updates |
|---|---|---|
| Active Directory Federation Services (AD FS) | Every AD FS server | SSL and Service Communications certificates. Restarts the AD FS service. |
| AD FS Web Application Proxy (WAP) | Every Web Application Proxy server | The proxy’s AD FS SSL certificate and, optionally, published application certificates. No restart. |
If your deployment has no WAP servers, use only the AD FS template.
Both templates need Windows Server 2016 or later.
Use an RSA certificate
AD FS only works with RSA certificates. The templates only appear for RSA certificates, so if you don’t see them, check the certificate’s key type in CertKit and reissue it as RSA.
AD FS servers
Install the agent and configure a deployment on every AD FS server.
- The primary server updates the farm’s SSL certificate bindings through WinRM. Allow WinRM between the AD FS servers.
- Each server restarts its AD FS service, which briefly interrupts sign-ins on that server. Use a deployment window to schedule this outside business hours.
- The template gives the AD FS service permission to read the new certificate’s private key. You don’t need to set this yourself.
Token-signing and token-decrypting certificates are not changed. AD FS renews those itself.
Web Application Proxy servers
Install the agent and configure the WAP template on every proxy server. Each proxy needs its own copy of the certificate.
Published application certificate update (auto or off) controls updates to other applications published through WAP:
auto(default): updates applications bound to an older certificate with the same subject. Applications using a different certificate are unchanged.off: only the AD FS certificate is updated.
Common problems
- One AD FS server still shows the old certificate: check that WinRM works between the primary server and that server, and that the template ran on the primary.
- Template isn’t offered for the certificate: the certificate isn’t RSA. Reissue it with an RSA key.
- A published app was skipped with a warning: the app’s current certificate isn’t installed on the proxy, so CertKit can’t tell whether it’s the same certificate. Update that app by hand once.
- The proxy update fails after the old certificate already expired: the proxy has lost its trust with AD FS. Run
Install-WebApplicationProxy -CertificateThumbprint <thumbprint>on the proxy to reconnect it, then deploy again.
For a product overview, see certificate automation for AD FS.