Skip to content

← All integrations

Windows · Identity and remote access

Replaces the SSL and service communications certificate in Active Directory Federation Services.

The service agent on the server fetches the task from the appliance over outbound HTTPS on port 443 and installs the certificate locally on the server. The appliance never connects to the server.

What happens

  1. The service agent on the server fetches the task from the appliance over outbound HTTPS, port 443.
  2. The Windows basics first import the certificate into the Windows certificate store (LocalMachine\My).
  3. The certificate is assigned to the SSL bindings and the service communications role in AD FS. If it fails: Rollback puts the previous certificates back on both.
  4. Verification: the package checks that both use the new certificate.

Technical details

Connection
The package runs through the service agent on the server. The agent connects over outbound HTTPS to the appliance, port 443 by default. You open no port into the server.
Service ports
443
You need
The service agent installed on the server. The agent on an AD FS federation server with the AD FS PowerShell module.
Platform
AD FS 3.0 and later, Windows Server 2012 R2 and later
Actions
Discovery, Installation, Verification, Rollback
Packages
windows-adfs

Get started