Jump to content

Recommended Posts

Posted

@derekgreen

Your single sign on trust certificate has expired. You need to login with the bypass option into the admin took and then reenter the URL to import the certificate from your SSO source system.

I dig out the bypass option option URL and add it too this post shortly.

Cheers

Martyn

Posted

A recent Post from Gerry details how to update your Single Sign On Configuration to contain the updated Certificate from your ADF Servers.
 

Kind Regards

Trevor Killick

Posted

Thanks guys. All of our ADFS configuration was done by a third party. How do I actually identify and update the certificate? I have attached a snip of the certificate(s) as presented in our SSO config.

certificate.PNG

Posted

@derekgreen

Hopefully you have the endpoint URL of your ADFS server which you can use to import an updated certificate from. Our is along the lines of https://......../federationmetadata/2007-06/federationmetadata.xml but would be specific to your provider. Once you have this you can click on the button in the top right hand corner to sso.JPG.8cf65ae3083a656bb57848dac71d046a.JPG to enter the endpoint an re-import an updated trust certificate in the dialog window that appears.

sso2.JPG.b85e301cddcd388de794c8637bcfeb92.JPG

 

As as workaround to get live app users in you could temporarily disable the SSO config and then choose to create passwords from the admin tool for your key users, whilst you sort out the SSO config.

Cheers

Martyn

 

Posted

@derekgreen as @Martyn Houghton suggested you need either teh URL or the SAML metadata file (the XML file). You need to ask the ADSF guy to give you this. They know what it is. Until you get this you can temporarily disable certificate validation to allow your users to log in.

EDIT: @Martyn Houghton disabling SSO allogether is indeed an option, but if you have hundreds of basic users.. well.. it might take a while to reset all passwords :D

Posted

@derekgreen I'm afraid can't... I simply don't know the product (ADFS) :( ... I can work with the XML file (or information) provided by the IdP (in this case ADFS) but to go in and look for it in the IdP itself I do not know :(

Posted

If you have revert to the username/password option (not SSO), you don't need to reset the password individually. Tell your customers to use the forgot password option to reset it themselves.

Regards

Nasim

forgot.PNG

  • Like 1
  • 2 months later...
  • 1 month later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...