ADFS Certificate Renewal
Certificate Re-key or Renewal Instructions
- Create a Certificate Singing Request – https://support.godaddy.com/help/article/4800/generating-iis-7-csrs-certificate-signing-requests
- When you receive the email confirmation you have 72 hours to install the new Certificate, otherwise the old certificate will be revoked.
- Import the Certificate into IIS – https://support.godaddy.com/help/article/4801/installing-an-ssl-certificate-in-microsoft-iis-7?locale=en
- Export the Certificate from IIS into .pfx format; to be used on other IIS servers
- Import the Certificates into Local Computer Intermediate CA and Personal
- For ADFS/CRM – Using Certificate Manager – Select the Certificate located in Personal and Select – Manage Private Keys and give NETWORK SERVICE and CRM APP rights to the Certificate. Check the Application pool to see what account CRM is running
- Do this on both CRM and ADFS Server
- http://support.microsoft.com/kb/2921805
- http://support2.microsoft.com/kb/2686840