SOLVED
Home

Configuring DRS (Device Registration Service) in installed ADFS Farm

%3CLINGO-SUB%20id%3D%22lingo-sub-197078%22%20slang%3D%22en-US%22%3EConfiguring%20DRS%20(Device%20Registration%20Service)%20in%20installed%20ADFS%20Farm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-197078%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20All%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EADFS%20is%20deployed%20in%20our%20environment%20and%20SSL%20certificate%20has%20subject%20alternative%20name%20(SAN)%20entries%20for%20required%203%20domains%3A%3C%2FP%3E%3CP%3Ests.domain1.com%3CBR%20%2F%3Ests.domain2.com%3C%2FP%3E%3CP%3Ests.domain3.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20now%20we%20have%20another%20requirement%20for%20DRS%20(Device%20Registration%20Service)%20to%20be%20configured.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20there%20are%20no%20SAN%20entries%20in%20the%20SSL%20certificate%20installed%20on%20our%20ADFS%20farm%3A%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CSTRONG%3E%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3Eenterpriseregistration.domain1.com%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CBR%20%2F%3Eenterpriseregistration.domain2.com%3CBR%20%2F%3E%3CBR%20%2F%3Eenterpriseregistration.domain3.com%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDo%20we%20have%20to%20deploy%20new%20SSL%20certificate%20with%20SAN%20entries%20for%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3Eenterpriseregistration.domain1.com%2C%20enterpriseregistration.domain2.com%2C%20enterpriseregistration.domain3.com%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3F%3C%2FP%3E%3CP%3EDo%20we%20have%20to%20reconfigure%20ADFS%20farm%20again%3F%3C%2FP%3E%3CP%3EIs%20it%20possible%2C%20we%20only%20have%20to%20change%20SSL%20certificate%20with%20required%20new%20entries%20and%20we%20dont%20redeploy%20ADFS%20farm%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20help.%20I%20will%20appreciate%20your%20replies%20and%20solutions%20for%20given%20problem.%3C%2FP%3E%3CP%3EThanks%20again.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-197078%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-197441%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Configuring%20DRS%20(Device%20Registration%20Service)%20in%20installed%20ADFS%20Farm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-197441%22%20slang%3D%22en-US%22%3E%3CP%3EYes%20mate%2C%20then%20install%20that%20certificate%20on%20the%20ADFS%20servers.%20This%20will%20need%20to%20be%20under%20change%20control%20as%20you%20are%20revoking%20and%20re-keying%20your%20certificate%20so%20may%20cause%20a%20small%20outage....%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-197313%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Configuring%20DRS%20(Device%20Registration%20Service)%20in%20installed%20ADFS%20Farm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-197313%22%20slang%3D%22en-US%22%3EDo%20you%20mean%20to%20say%20the%20below%206%20SAN%20entries%3F%3CBR%20%2F%3E%3CBR%20%2F%3Eenterpriseregistration.domain1.com%3CBR%20%2F%3Eenterpriseregistration.domain2.com%3CBR%20%2F%3Eenterpriseregistration.domain3.com%3CBR%20%2F%3Ests.domain1.com%3CBR%20%2F%3Ests.domain2.com%3CBR%20%2F%3Ests.domain3.com%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-197259%22%20slang%3D%22en-US%22%3ERE%3A%20Configuring%20DRS%20(Device%20Registration%20Service)%20in%20installed%20ADFS%20Farm%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-197259%22%20slang%3D%22en-US%22%3ESounds%20like%20you%20just%20need%20to%20re-key%20and%20re-issue%20the%20certificate%20with%206%20SAN's%20and%20install%20it%20on%20your%20servers%20involved%20with%20ADFS%20and%20DRS%3C%2FLINGO-BODY%3E
Highlighted
amanpreet singh
Occasional Contributor

Dear All,

 

ADFS is deployed in our environment and SSL certificate has subject alternative name (SAN) entries for required 3 domains:

sts.domain1.com
sts.domain2.com

sts.domain3.com

 

But now we have another requirement for DRS (Device Registration Service) to be configured.

 

But there are no SAN entries in the SSL certificate installed on our ADFS farm:


enterpriseregistration.domain1.com


enterpriseregistration.domain2.com

enterpriseregistration.domain3.com

 

Do we have to deploy new SSL certificate with SAN entries for

enterpriseregistration.domain1.com, enterpriseregistration.domain2.com, enterpriseregistration.domain3.com

 ?

Do we have to reconfigure ADFS farm again?

Is it possible, we only have to change SSL certificate with required new entries and we dont redeploy ADFS farm?

 

Please help. I will appreciate your replies and solutions for given problem.

Thanks again.

3 Replies
Sounds like you just need to re-key and re-issue the certificate with 6 SAN's and install it on your servers involved with ADFS and DRS
Do you mean to say the below 6 SAN entries?

enterpriseregistration.domain1.com
enterpriseregistration.domain2.com
enterpriseregistration.domain3.com
sts.domain1.com
sts.domain2.com
sts.domain3.com
Solution

Yes mate, then install that certificate on the ADFS servers. This will need to be under change control as you are revoking and re-keying your certificate so may cause a small outage....

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies