{"id":1252,"date":"2017-05-11T10:29:55","date_gmt":"2017-05-11T08:29:55","guid":{"rendered":"http:\/\/svobodma.cz\/?p=1252"},"modified":"2018-06-15T09:28:50","modified_gmt":"2018-06-15T07:28:50","slug":"how-to-reconfigure-adfs-proxy-server","status":"publish","type":"post","link":"https:\/\/svobodma.cz\/?p=1252","title":{"rendered":"How to re-configure ADFS Proxy Server which reports problems"},"content":{"rendered":"<p><strong>How fix the problem in the picture ?\u00a0 Affected server was\u00a0 Sxxxxxxx.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Open up\u00a0Remote Access management console and You see\u00a0red. The red color is nice but in this case it means that something is wrong.<\/p>\n<p><a href=\"http:\/\/svobodma.cz\/?attachment_id=1264\" rel=\"attachment wp-att-1264\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1264\" src=\"http:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/1_LI.jpg\" alt=\"1_LI\" width=\"547\" height=\"287\" srcset=\"https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/1_LI.jpg 547w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/1_LI-150x79.jpg 150w\" sizes=\"auto, (max-width: 547px) 100vw, 547px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>We need to reset WAP configuration, in Registry we have to change value<strong> 2 = configured <\/strong>to the Value <strong>1 = not configured<\/strong><\/p>\n<p><a href=\"http:\/\/svobodma.cz\/?attachment_id=1265\" rel=\"attachment wp-att-1265\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1265\" src=\"http:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/2-2.png\" alt=\"2\" width=\"797\" height=\"577\" srcset=\"https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/2-2.png 797w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/2-2-768x556.png 768w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/2-2-150x109.png 150w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/2-2-560x405.png 560w\" sizes=\"auto, (max-width: 797px) 100vw, 797px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Use <strong>powershell.exe<\/strong> &#8211; <span style=\"color: #3366ff;\">\u00a0Install-WebApplicationProxy -CertificateThumbprint \u201cxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\u201d -FederationServiceName \u201cxxxxxx<strong>.com\u201d <\/strong><span style=\"color: #000000;\">(but it did not work for me same good as GUI for server ADFS 3.0 S2K12 R2 \ud83d\ude41 &#8230;.)<\/span><\/span><\/p>\n<p>or through console Remote Access management we configured WAP again. It requires name of ADFS service \u2013 <strong>xxxxxxxxxxx.com<\/strong>, usually service account &#8211;<strong> axxxxxx<\/strong>\u00a0 and choose the right certificate \u2013 \u00a0right ADFS certificate with name <strong>xxxxxxxxxxx.com<\/strong>. Although we did this, the service tried to use different, self-signed certificate , In ADFS event log we could see \u201eUnable to retrieve proxy configuration data from the Federation Service + thumbprint \u00a0of bad certificate not our ADFS certificate \u201c In mmc.exe we could see only the certificate for MS SCOM, <strong>xxxxxxxxxxx.com<\/strong> and some expirated self-signed certificates but we could not see the certificate with thumbprint found in event log. By Powershell \u00a0we could list it (example is below), we found bad certificate + others and we removed all certificates self-signed certificate.<\/p>\n<p>&nbsp;<\/p>\n<p>Get-WebApplicationProxySslCertificate,\u00a0Get-ChildItem -Path cert:\\LocalMachine\\My | FL FriendlyName, Thumbprint, Subject, NotBefore, NotAfter<\/p>\n<p><a href=\"http:\/\/svobodma.cz\/?attachment_id=1266\" rel=\"attachment wp-att-1266\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1266\" src=\"http:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/3_LI.jpg\" alt=\"3_LI\" width=\"838\" height=\"324\" srcset=\"https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/3_LI.jpg 838w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/3_LI-768x297.jpg 768w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/3_LI-150x58.jpg 150w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/3_LI-560x217.jpg 560w\" sizes=\"auto, (max-width: 838px) 100vw, 838px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>When we removed the self-signed certificates, we tried to complete the wizard again and it was success<\/p>\n<p><a href=\"http:\/\/svobodma.cz\/?attachment_id=1267\" rel=\"attachment wp-att-1267\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1267\" src=\"http:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/4_LI.jpg\" alt=\"4_LI\" width=\"516\" height=\"370\" srcset=\"https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/4_LI.jpg 516w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/4_LI-150x108.jpg 150w\" sizes=\"auto, (max-width: 516px) 100vw, 516px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Now it is working well. Do not worry that we see server xxxxxx\u00a0twice, we could see it because in my case we configured WAP after the server has been configured with postfix (full computer name), because for MS SCOM monitoring it is require.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/svobodma.cz\/?attachment_id=1268\" rel=\"attachment wp-att-1268\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1268\" src=\"http:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/5_LI.jpg\" alt=\"5_LI\" width=\"1042\" height=\"269\" srcset=\"https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/5_LI.jpg 1042w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/5_LI-768x198.jpg 768w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/5_LI-150x39.jpg 150w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/5_LI-560x145.jpg 560w\" sizes=\"auto, (max-width: 1042px) 100vw, 1042px\" \/><\/a> <a href=\"http:\/\/svobodma.cz\/?attachment_id=1269\" rel=\"attachment wp-att-1269\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1269\" src=\"http:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/6_LI.jpg\" alt=\"6_LI\" width=\"830\" height=\"201\" srcset=\"https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/6_LI.jpg 830w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/6_LI-768x186.jpg 768w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/6_LI-150x36.jpg 150w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/6_LI-560x136.jpg 560w\" sizes=\"auto, (max-width: 830px) 100vw, 830px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>The result of testing availability <a href=\"https:\/\/sts.ga.adientpartners.com\/adfs\/ls\/IdpInitiatedSignon.aspx\">https:\/\/[name of your ADFS]\/adfs\/ls\/IdpInitiatedSignon.aspx<\/a> from internet. Tested from page &#8211; <a href=\"https:\/\/www.site24x7.com\/check-website-availability.html\">https:\/\/www.site24x7.com\/check-website-availability.html<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/svobodma.cz\/?attachment_id=1270\" rel=\"attachment wp-att-1270\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1270\" src=\"http:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/7_LI.jpg\" alt=\"7_LI\" width=\"823\" height=\"639\" srcset=\"https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/7_LI.jpg 823w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/7_LI-768x596.jpg 768w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/7_LI-150x116.jpg 150w, https:\/\/svobodma.cz\/marwin.e-blog.cz\/httpdocs\/wp-content\/uploads\/7_LI-560x435.jpg 560w\" sizes=\"auto, (max-width: 823px) 100vw, 823px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How fix the problem in the picture ?\u00a0 Affected server was\u00a0 Sxxxxxxx. &nbsp; Open up\u00a0Remote Access management console and You see\u00a0red. The red color is nice but in this case it means that something is wrong. &nbsp; &nbsp; We need &hellip; <a href=\"https:\/\/svobodma.cz\/?p=1252\">Cel\u00fd p\u0159\u00edsp\u011bvek <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[],"class_list":["post-1252","post","type-post","status-publish","format-standard","hentry","category-adfs"],"_links":{"self":[{"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/posts\/1252","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/svobodma.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1252"}],"version-history":[{"count":8,"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/posts\/1252\/revisions"}],"predecessor-version":[{"id":1304,"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/posts\/1252\/revisions\/1304"}],"wp:attachment":[{"href":"https:\/\/svobodma.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1252"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/svobodma.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1252"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/svobodma.cz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1252"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}