Tuesday, 10 March 2015

Active Directory Certificate Services (AD CS) Root Certificate Authority “A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. 0x800b0109 (-2146762487 CERT_E_UNTRUSTEDROOT)"

I am not sure quite how this happened, I was in the middle of configuring the root certificate authority using my notes which I have implemented loads of AD CS infrastructures (http://blog.ryanbetts.co.uk/2015/01/implementing-two-tier-active-directory.html) and until today I have never had this issue before. The only thing was that VMware Tools restarted the VM when I was in the middle of configuring the Certificate Authority.
When you try and start the AD CS service you are faced with the error “A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. 0x800b0109 (-2146762487 CERT_E_UNTRUSTEDROOT)”.

It was a simple fix, but threw me for a minute. You need to manually import the root certificate that is generated and placed in the C:\Windows\System32\CertSrv\CertEnroll folder on the root certificate authority itself. 

Install the certificate in the Local Computer store and have the wizard automatically choose which store it places the certificate into.

You should then be able to start the AD CS service.

Friday, 6 March 2015

Office 365 Installing and Configuring Active Directory Federation Services (AD FS) with a Trusted SSL Certificate

This post is a follow on from my last two blog posts on configuring Office 365, DirSync and AD FS for unified identities from your on-site Active Directory to the Office 365 cloud. 

If you review this TechNet article (https://technet.microsoft.com/en-us/library/cc730660.aspx) you will see that AD FS requires a globally trusted SSL certificate if you are going to federate to Office 365 for Single Sign On (SSO). Although it would be possible to use your internal Certificate Authority if your CRL's were published externally it is recommended to use an SSL certificate issued from a global provider. As this is only a test lab I got a cheap SSL certificate from GoDaddy for £5.

Getting the certificate successfully installed so that AD FS can use it can be confusing at first, when GoDaddy issue certificates they come in the .CER format, which when imported into the AD FS server do not show up when you run the AD FS configuration wizard.

I found the easiest way to get round this is to download the DigiCert utility from here https://www.digicert.com/util/, once it's installed open the GUI. Click on the SSL icon from the left hand side and then click Import.


Once you have downloaded your SSL certificate from your certificate provider browse to the location of the file and click Next.


Enter a friendly name for the certificate, I have just used the single Common Name in this instance. Click Finish.


The certificate will then be listed in the DigiCert utility, click on the certificate once and then click Export Certificate.


Choose Yes Export the Private Key and ensure the format is set to PFX and include all related certificates, click Next.


You will be prompted for a password to protect the certificates private key, click Next.


Point to a path to output the new certificate file. Click Finish.


Get the newly generated certificate PFX file onto the AD FS server and right click on it, and select Install PFX.


Run through the Certificate Import Wizard, ensuring you have to import it in to the Local Machines Certificate store.



You will be required to enter the password that you set during the DigiCert utility stage. Ensure you make the key exportable as you will need to export this if you are going to use the AD FS WAP. Click Next.



Now it's time to install Active Directory Federation Services, open Server Manager and click Manage then Add Roles and Features.


Click Next and select AD FS from the list of available server roles, click Next.




Once the installation has completed, return to Server Manager and click on the yellow icon and select Configure the Federation Service on this Server.


Once the wizard launched select Create the first federation server in a federation server farm and then click Next.



Now you will be prompted to select the SSL Certificate you would like AD FS to use, from the drop down the certificate you imported in the last stage should appear here, click Next.


An AD FS Service Account is required, then click Next.


In this example I am going to install AD FS with the Windows Internal Database it is possible to configure AD FS to use full SQL Server but it's only for large environments that require over 5 AD FS servers in a farm. Click Next.


Click Next, and the wizard will configure the basic AD FS settings.



Office 365 Configuring Active Directory Synchornization with Azure AD DirSync

Login to your Office 365 tenant and navigate to the Admin Console page, click on Users and then Active Users. From there click Active Directory Sync Set Up

You will then be faced with 7 options, click on option 3 Active Directory Synchronization and click on Active.

You will be asked to confirm you want to ensure Active Directory sync, click Yes.

As I am doing this in a brand new Active Directory I did not bother running the IdFix Tool, but if you are running this in your production Active Directory that may need checking you should run this tool.


Stage 5 requires you to download the Azure AD Dir Sync tool, click Download and it will start, the download is around 200MB's. 

Once the Dir Sync tool has downloaded, double click on the exe file to run the setup. Click Next.

Accept the License Terms and click Next.

The Dir Sync wizard will then begin installing the required components.


Choose to start the configuration wizard.


Click Next.


Enter the credentials you used to configure your Office tenant.


Now local domain credentials are required.


Do not choose to configure a Hybrid Deployment.


Ensure you choose to configure Password Sync as this will be a good fall back if your AD FS infrastructure fails, if DirSync is configured to sync passwords users will still be able to login to Office 365 using their domain credentials.



Kick off a sync job and click Finish.


To test the users have been synced to the Office 365 tenant check with in the console.


Office 365: Configuring your E3 Trial Tenant for First Use!

If you are thinking about Office 365, you can get a full trial from Microsoft using their E3 (or Enterprise 3) subscription. Search Google for a trial and you can sign up for 30 days.
When you get to the stage of registering you will at first be configured to use an .onmicrosoft.com domain name, so you first must configure a Global Administrator account. 


Once your tenant has been provisioned click on the Option tile and click Admin.

The first stage is to get your full qualified domain name configured to operate with your Office 365 tenant, to do this click on Domain and then click Add Domain.

You will be prompted by a wizard to help walk you through configuring DNS to ensure you own the FQDN you entered in the last stage, click on Let's Get Started.

Enter the domain name you intend to use and click Next.

One of the ways you can confirm you own the domain is by configuring a TXT Record on your public DNS, Office 365 generates a TXT Value for you to do this.

Open up your DNS registra's Manage your DNS console and create a new TXT Record with the values listed from your Office 365 tenant. My DNS is managed by 123Reg so you can see how I did it for them.

Click Confirm and if you have done it correctly, Microsoft should be able to confirm you own the domain and you will receive the following screen, click on Next.

The next step is to configure your Office 365 users with a valid e-mail address at your new fully qualified domain, as the original tenant only has a single user ensure the account is ticked and click Update Selected Users.

It should be done without hitch, you will then be prompted to logout and then in with your new username at your FQDN. This means your .onmicrosoft.com domain suffix is no longer used for login to the Office 365 admin console.

Login with the new user account.

You will be prompted with another wizard to configure your DNS so that all of the Office 365 services operate properly. Click Next.

I personally host my DNS using 123Reg so I have chosen to select No, I have an existing website or prefer to manage my own DNS records and click Next. You can of course configure Microsoft to host your DNS globally.

For this example I am going to configure Office 365 with all the services available within the E3 subscription. Click Next.

You must then return to your domains DNS control panel and configure the following records with the values set for your Office 365 tenant.

Once you have done that click on Okay, I've added the records.

The tenant is now setup with your FQDN and should be operational with basic features. This was an introductory post before I document the setup of DirSync and AD FS for single sign on with Office 365 and Active Directory.