<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results for 'app:weblogs' matching tags 'Certificates' and 'SP1'</title><link>http://msmvps.com/search/SearchResults.aspx?q=app:weblogs&amp;tag=Certificates,SP1&amp;orTags=0&amp;o=DateDescending</link><description>Search results for 'app:weblogs' matching tags 'Certificates' and 'SP1'</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Replacing a Federation Trust Certificate When the Original Certificate is Missing</title><link>http://msmvps.com/blogs/expta/archive/2010/10/23/replacing-a-federation-trust-certificate-when-the-original-certificate-is-missing.aspx</link><pubDate>Sat, 23 Oct 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1780552</guid><dc:creator>Anonymous</dc:creator><description>Exchange 2010 federation allows organizations to share calendar free/busy information (also known as calendar availability) and contact information with external recipients, vendors, partners, and customers.&amp;nbsp; This is accomplished by creating a trust with Microsoft&amp;#39;s Federation Gateway.&amp;nbsp; This cloud-based service offered by Microsoft acts as the trust broker between your on-premises Exchange&amp;nbsp;2010&amp;nbsp;organization and other federated&amp;nbsp;Exchange&amp;nbsp;2010&amp;nbsp;organizations.&amp;nbsp; For more information about Exchange federation, see &lt;a href="http://technet.microsoft.com/en-us/library/dd335047.aspx" target="_blank"&gt;Understanding Federation&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;To configure federation you install an Exchange certificate, enable the certificate for Federation, and create a federation trust with Microsoft Federation Gateway.&amp;nbsp; Eventually you will need to replace this certificate, either for business reasons or when&amp;nbsp;the certificate expires.&amp;nbsp; The usual way of doing this is to install a new Exchange certificate and configure it as the &amp;quot;Next Certificate&amp;quot; in the Manage Federation Certificate wizard, as shown below.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear:both;text-align:center;"&gt;&lt;a href="http://1.bp.blogspot.com/_IsItvsG4t0k/TMJtpNWaZ7I/AAAAAAAAF2o/3kyWrboJEHA/s1600/Wizard.png" style="margin-left:1em;margin-right:1em;"&gt;&lt;img border="0" height="350" src="http://1.bp.blogspot.com/_IsItvsG4t0k/TMJtpNWaZ7I/AAAAAAAAF2o/3kyWrboJEHA/s400/Wizard.png" width="400" alt="" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear:both;text-align:center;"&gt;&lt;br /&gt;&lt;/div&gt;When you&amp;#39;re ready to replace the current federation certificate you simply run the Manage Federation wizard, select the &amp;quot;&lt;strong&gt;Roll certificate to make the next certificate as the current certificate&lt;/strong&gt;&amp;quot; check box, and complete the wizard.&amp;nbsp; What was the Next Certificate becomes the Current Certificate, and the Current Certificate becomes the Previous Certificate.&lt;br /&gt;&lt;br /&gt;I ran into an interesting issue where the process above did not work.&amp;nbsp; The customer deleted the Current Certificate from the computer&amp;#39;s local certificate store, rather than roll the Next Certificate into the current certificate&amp;#39;s place.&amp;nbsp; This causes the Manage Federation wizard t break because it can&amp;#39;t locate the Current Certificate.&amp;nbsp; I was also unable to use the &lt;strong&gt;Set-FederationTrust&lt;/strong&gt; cmdlet in EMS - it would give the same error:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;, Courier, monospace;"&gt;[PS] C:\&amp;gt;&lt;strong&gt;Set-FederationTrust -Identity &amp;quot;Microsoft Federation Gateway&amp;quot; -PublishFederationCertificate&lt;br /&gt;&lt;span style="color:red;"&gt;Federation certificate with the thumbprint &amp;quot;29FD8FFF241A4317ABAAF326226BC209F682C2F3&amp;quot; cannot be found.&lt;/span&gt;&lt;/strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + CategoryInfo&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : InvalidResult: (:) [Set-FederationTrust], FederationCertificateInvalidException&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + FullyQualifiedErrorId : 906B427C,Microsoft.Exchange.Management.SystemConfigurationTasks.SetFederationTrust&lt;/span&gt;&lt;/blockquote&gt;To fix this, you&amp;#39;ll need to do it using ADSIEdit.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Log into a&amp;nbsp;computer with administrator rights and run &lt;strong&gt;ADSIEdit.msc&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Connect to the &lt;strong&gt;Configuration&lt;/strong&gt; naming context&lt;/li&gt;&lt;li&gt;Navigate to&amp;nbsp;&lt;strong&gt;CN=Federation Trusts,CN=&lt;em&gt;OrgName&lt;/em&gt;,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=&lt;em&gt;domain&lt;/em&gt;,DC=com&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Right-click &lt;strong&gt;CN=Microsoft Federation Gateway&lt;/strong&gt; in the work pane and select &lt;strong&gt;Properties&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Edit the &lt;strong&gt;msExchFedOrgNextCertificate&lt;/strong&gt; property (which contains the thumbprint of the Next Certificate) and copy the entire value.&amp;nbsp; Close the &lt;strong&gt;msExchFedOrgNextCertificate&lt;/strong&gt; property.&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear:both;text-align:center;"&gt;&lt;a href="http://2.bp.blogspot.com/_IsItvsG4t0k/TMJ3nt64GGI/AAAAAAAAF2s/Bw1FL6Om2NE/s1600/Next+Cert.png" style="margin-left:1em;margin-right:1em;"&gt;&lt;img border="0" height="263" src="http://2.bp.blogspot.com/_IsItvsG4t0k/TMJ3nt64GGI/AAAAAAAAF2s/Bw1FL6Om2NE/s400/Next+Cert.png" width="400" alt="" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Edit the &lt;strong&gt;msExchFedOrgPrivCertificate&lt;/strong&gt; property (which contains the thumbprint of the Current Certificate, which was removed) and paste the value.&amp;nbsp; Click &lt;strong&gt;OK&lt;/strong&gt; to set the value.&lt;/li&gt;&lt;li&gt;Wait for the change to replicate throughout your AD infrastructure.&lt;/li&gt;&lt;li&gt;From the Exchange Management Console, run the Manage Federation Wizard.&amp;nbsp; You will now notice that the Current Certificate and the Next Certificate are the same.&lt;/li&gt;&lt;li&gt;Check &lt;strong&gt;Roll certificate to make the next certificate as the current certificate&lt;/strong&gt; and complete the wizard.&lt;/li&gt;&lt;/ul&gt;Don&amp;#39;t forget to test your configuration with the &lt;strong&gt;Test-Federation&lt;/strong&gt; cmdlet.&lt;div class="blogger-post-footer"&gt;Did you find this information useful? Post a comment and share it with others!&lt;img width="1" height="1" src="https://blogger.googleusercontent.com/tracker/798194812750898417-8489339796175204739?l=www.expta.com" alt="" /&gt;&lt;/div&gt;</description></item></channel></rss>