문제

On Windows Server 2012, where does ADFS store the automatically generated Token-Decrypting certificate?

I manually checked the usual places and could not find it: C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys

I was able to identify the Service-Communications cert and Token-Signing certificate.

도움이 되었습니까?

해결책 2

ADFS was configured to run under a specific account, the certificate was located under there Roaming profile. This path is only applicable for certficates that are automatically generated when ADFS is first configured. Once expired, I recommend installing a new cert is LocalMachine store instead.

C:\Users\<AccountNameRunningADFS>\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates

다른 팁

On our boxes (WID / automatic rollover), they are stored in a container in AD under:

Program Data / Microsoft / ADFS

Self-signed certificates are stored in the SQL / WID database, not the Certificates MMC

라이센스 : CC-BY-SA ~와 함께 속성
제휴하지 않습니다 StackOverflow
scroll top