AD FS Token issuance endpoints for Windows authentication fail to open

Hi,
I have had issue with AD FS and after turning tracing on, I realized that the AD FS endpoints to issue token based on windows authentication were all failing with an error like:
A WS-Trust endpoint that was configured could not be opened. 
Additional Data 
Address: https://adfsvm.dub01.local/adfs/services/trust/13/windowstransport 
Mode:    WindowsTransport 
Error: 
MSIS0006: A Service Principal Name is not registered for the AD FS service account. 
I have tried to register an SPN for the AD FS service using the following command (I have found the AD FS Service Name in the Federation Service Properties as in the screenshot hereunder) but it fails with the following error.
setspn -a host/ADFSVM.dub01.local DUB01\ADFSService
Checking domain DC=dub01,DC=local
CN=ADFSVM,CN=Computers,DC=dub01,DC=local
        WSMAN/ADFSVM
        WSMAN/ADFSVM.dub01.local
        TERMSRV/ADFSVM
        TERMSRV/ADFSVM.dub01.local
        RestrictedKrbHost/ADFSVM
        HOST/ADFSVM
        RestrictedKrbHost/ADFSVM.dub01.local
        HOST/ADFSVM.dub01.local
Duplicate SPN found, aborting operation!
Now I have come to realise that the Federation Service name is the same as the computer name but:
I dont know if that is an issue
I don't recall having been offered to give a particular name when installing AD FS
This is the first time I install AD FS. Is there anyone who could give me a pointer?
Thanks.
Francois

the ADFS federation service FQDN should NOT be the same as the hostname. You will run into Kerberos issues because of duplicate SPNs as you have found
https://jorgequestforknowledge.wordpress.com/2013/09/06/duplicate-spn-breaks-trust-between-clientserver-and-active-directory/
When installing ADFS you should specify a federation service FQDN and a service account. When using the GUI to install ADFS, (if I'm not mistaken) the federation service FQDN is derived from the selected cert in the GUI. If that cert had a subject name being
the hostname, you get this scenario. Instead, install an SSL cert, a token signing cert and a token encryption cert BEFORE the installation and use powershell to install/configure ADFS as it gives you more control.
As an example see (ADFS v2):
https://jorgequestforknowledge.wordpress.com/2012/05/08/installing-and-configuring-adfs-v2-as-an-sts-server-part-1/
https://jorgequestforknowledge.wordpress.com/2012/05/09/installing-and-configuring-adfs-v2-as-an-sts-server-part-2/
https://jorgequestforknowledge.wordpress.com/2012/05/10/installing-and-configuring-adfs-v2-as-an-sts-server-part-3/
Install-ADFSFarm
https://technet.microsoft.com/en-us/library/dn479416.aspx
Cheers,
Jorge de Almeida Pinto
Principal Consultant | MVP Directory Services | IAM Technologies
COMMUNITY...:
DISCLAIMER: This post is provided "AS IS" with no warranties of any kind, either expressed or implied, and confers no rights! Always evaluate/test yourself before using/implementing this!

Similar Messages

  • ACS SE setup for windows authentication

    Dear All,
    I'm trying to install an ACS Solution Engine in My network for access control (AAA). I succeed in setting up authentication using the internal database and that works fine. Now My boss want users to be authenticated through an external database (windows AD). I tried achieving this but kept getting different errors.(like EAP-TLS or PEAP authentication failed during SSL handshake) or (Authen session timed out: Challenge not provided by client).
    Please I need someone who has done this setup successfully before to give Me a step by step procedure on how I can setup ACS SE for windows authentication using My domain windows authentication.
    Thanks

    Dear All,I'm
    trying to install an ACS Solution Engine in My network for access
    control (AAA). I succeed in setting up authentication using the
    internal database and that works fine. Now My boss want users to be
    authenticated through an external database (windows AD). I tried
    achieving this but kept getting different errors.(like EAP-TLS or PEAP
    authentication failed during SSL handshake) or (Authen session timed
    out: Challenge not provided by client).Please
    I need someone who has done this setup successfully before to give Me a
    step by step procedure on how I can setup ACS SE for windows
    authentication using My domain windows authentication.Thanks
    Hi,
    Check out the belwo link on your query,Hope that help !!
    https://supportforums.cisco.com/docs/DOC-5542
    If helpful do rate
    Ganesh.H

  • Error 0x80090318 and lots of other errorsI live in Iran  Yesterday i wanted to use itunes store for windows ; when i have open itunes it gives me the error 0x80090318 .  I have search the wb alot and i have check lots of Iranian and English website but ha

    I live in Iran
    Yesterday I wanted to use iTunes store for windows ; when i have open iTunes it gives me the error 0x80090318 .
    I have search the web alot and i have check lots of Iranian and English website but have not find any solution for
    this problem . Today I have find a software called "Hide my IP" i have opened up that
    when this software was opened , itunes have said "iTunes can't verify the identify of the server "init.itunes.apple.com"".
    then i have click on "continue" then iTunes said "iTunes could not connect to the iTunes Store. An unknown error occurred (310)."
    And theres a matter that i think that have a connection with this topic and thats , that when i want to go to the lots
    of websites like Google Yahoo! Mail and lots of other website my both browser ( FireFox and IE ) will say" This connection is untrusted " .
    I think the solution of my second problem is the solution of my first problem too !

    Tried all the rest on this site did not work for me
    Follow the link below & this one sorted it for me, it was a conflict in programs using Winsock & I got rid of my old program,
    Sorted.
    http://support.apple.com/kb/TS4123
    Tom Ireland

  • I downloaded adobe Reader XI sucessfully for Windows but I cannot open pdfs.

    I downloaded adobe Reader XI sucessfully for Windows but I cannot open pdfs.
    Any suggestions?

    I am able to open them now, but I have to open the program first and then open the file through that. This doesn't make sense why I can't just open by clicking on the file.

  • Windows setup failed to open distribution share d:\ds when trying to run the windows embedded standard 7 image builder wizard

    The wizard fails with: windows setup failed to open distribution share d:\ds (..etc)
    I am running it from a USB disk that has over 4GB free space, all the other files and folders are shown in the DS folder ok
    Please advise what i should do here?
    Does the drive need to be a certain format? its FAT32 at the moment (not NTFS, so no security)
    I have tried copying the contents of the wes7-ibw iso to another USB drive and the same thing happens.

    I solved it : setup failed to open distribution share d:\ds  ... error 0x8007000    /0x8007003
    the cause I assume there is something strange about the CD file format on that disk.
    I first created a bootable usb (diskpart) then as i didnt had software to do it all in once
    i converted the original CD to iso, and used other software to burn an ISO as bootable CD on usb.
    ( i used iso to usb for that its free )
    i ve tried it with the usb as fat32 and (using convert converted fat32 to NTFS (stayed bootable).
    I even tried different hard disks no difference same error.
    Each time same error.
    Then in the end i noticed the folder content of the DS folder on USB and CD wasn't equally.
    So then i copied directories one by one over their existing USB counterparts
    After that it worked...
    Maybe the CD isnt folowing some CDrom standards, or uses a rarely used format; not wel recognized by common CDrom tools

  • IIsProxy version for windows authentication

    We are in the process of installing windows authentication to our EP 6.0 portal. We are running on SP 11 J2EE with portal SP 11 patch 3. 
    The first question I have in document “Using Header variables or Integrated Windows Authentication” section “Installing the IIsProxy module” says for security reasons we need to install version 1.7.0.0. Was this version released, we cannot find it on the service market place?
    My second question, when we use version IISPROXY16_2-10001433.SAR the authentication mechanism works fine to the portal but I cannot navigate within the portal, it looks like the screen get stuck on the first Iview no matter what role you choose. When we use version IISPROXY15_0-10001969.SAR things work fine. I increased the trace while using IISProxy 16.2 but there were no errors in the logs. We would like to be on the latest version. Any idea what might be the problem?
    Thanks for your help,
    Mike Fasheh

    Hi folks !
    I have made this configuration a couple of times without problems (other iisproxy version), but for some reason this time is not working and Im totally desesperated =(
    Scenario:
    - 1st server, win 2003, iis 6.0: Iisproxy 1.6.2 installed, it forwards the requests correctly
    - 2st. server, ibm with aix, sap ep 6.0 sp12. Configurations made for NT authentication.
    The problem:
    For some reason the virtual directories defined in IisProxy.xml file are not taking the IIS Security Settings (Integrated Windows Authenticated). The iisproxy is just forwarding the request, but the IIS is not making the NT authentication.
    If I change the name of the virtual directory in the IisProxy.xml file (put any name). In this case, IIS applies the security settings correctly.
    Any clue about this ?
    Thanks a lot for your help !!!!!!
    Regards from Mexico,
    Diego

  • Support for Windows Authentication in SQL Server Plug-in

    I can't find anything in the documentation, or maybe my eyes are subconsciously skipping over the section. Does the 3.2.3.1.0 SQL Server plug-in support Windows Authentication? We have stopped using Mixed-Mode in our SQL Server 2005 Databases.

    Not as such, but you can always manage them through worksheet statements.
    You can request this at the SQL Developer Exchange though, so other users can vote and add weight for possible future implementation.
    Regards,
    K.

  • Jabber for Windows Login failed with - "Must change at Next Login" for CUCM Authentication

    Jabber for Windows users cannot login when "User Must Change at Next Login" is selected in the CUCM credential Policy
    I found this Bug-ID: CSCuh84476
    https://tools.cisco.com/bugsearch/bug/CSCuh84476
    We use Jabber for Windows 9.7.4!
    I just want to know if there are other users have the same problem and which workaround they applied.
    I’m currently testing a User with different Policy credentials (Credentials expire after 1 day).
    I think this will also lead to a “username or password wrong”-popup but tomorrow I will see it myself ;)
    The planed workaround for us will be to set the “User Must Change at Next Login ” option and the users first have to login at UCM-Userpage to change their initial password.
    BTW: Maybe somebody from Cisco know when this get fixed?
    Best regards
    Franz

    J4W does rely very heavily on DNS, you should at least all required entries to hosts and lmhosts.
    How are your servers defined under system -> server??
    Are you able to log into UCMuser page??
    Have you properly configured all user/device/line association, and created the necessary service profiles???

  • Can't obtain an access token for Translator - Authentication failed.

    Hi,
    I copied the PHP code at http://msdn.microsoft.com/en-us/library/hh454950.aspx, pasted it into a file, and made a simple AJAX call to it. I have checked to make sure that the client id and client secret are correct. Somehow it returned an error message
    saying: Exception-ACS50012: Authentication failed.
    I read somewhere here that we can only use numeric digits for the client id so I changed the client id to a number. However that still didn't work.
    Please help.

    Hi,
    I'm glad to hear that you have solved your issue, if you have any issues later, welcome to our forum again.
    Best Regards
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • Windows authentication fails from Mac browser when LB is in between

    (1)     A new instance of Windows server 2008 R2 is taken and IIS server is installed.
    On IIS server, ‘Windows Authentication’ is enabled and all the other authentication (anonymous, basic) is disabled.
    (2)     From Safari browser on Mac, a IIS resource (protected by Windows Authentication) is accessed by directly accessing IIS server. The resource access is successful.
    (3)     Now a Load Balancer is configured in front of IIS server.
    (4)     From Safari browser on Mac, a IIS resource (protected by Windows Authentication) is accessed by accessing load balancer. Here IIS server prompts for username and password.
    Seems that authentication negotiation is failing between Mac browser and IIS when LB is in between. Can somebody pls know the reason / resolution for this issue ?
    Thanks

    I was just helping someone with this same issue, and found this post searching for answers. I think it's a problem with your web hosting provider. It looks like whois is saying you both use readyhosting.net, is that right?
    If you go into the developer options and override the User Agent string, you can make the issue start and stop. When the user agent string starts with "Mozilla/5.0 (Windows NT 6.1", then the page with show the error message. If it starts with anything else, then it works fine.
    This, and the fact that you did not make any changes to your site makes it sound like your hosting provider changed something. You probably need to have them fix it somehow.

  • I have uninstalled and reinstalled and Firefox for windows 7 will not open. There is no error message--it just doesn't open, even in safe mode. What do I do?

    My computer is set to auto update for Windows 7 Home Premium and for Microsoft Office Professional Plus 2010. I am also running Norton 360. There was a major update for Office on 12/10/14 that seems to be when my problems started. This month, every time my updates have caused a reboot, Mozilla has failed to open. I have uninstalled it and reinstalled it several times, and it has only lasted a day or two before it crashes again. This last time it will still not open. All the instructions to troubleshoot seem to be based on the idea that the program is open and just has issues. I can't even get it to open up in Safe Mode.
    I have tried to reinstall, and it says that it will launch automatically when the install is complete, but it is not working. Since Norton scans every download before it runs, I'm not certain if that is where the problem is since I never get the window that shows the step by step installer for Firefox.
    What do I need to do?

    Certain Firefox problems can be solved by performing a ''Clean reinstall''. This means you remove Firefox program files and then reinstall Firefox. A clean reinstall is not the same as a regular reinstall performed using the built in installer. Please follow these steps:
    '''Note:''' You might want to print these steps or view them in another browser.
    #Download the latest Desktop version of Firefox from [https://www.mozilla.org mozilla.org] (or choose the download for your operating system and language from [https://www.mozilla.org/firefox/all/ this page]) and save the setup file to your computer.
    #After the download finishes, close all Firefox windows (or open the Firefox menu [[Image:New Fx Menu]] and click the close button [[Image:Close 29]]).
    #Delete the Firefox installation folder, which is located in one of these locations, by default:
    #*'''Windows:'''
    #**C:\Program Files\Mozilla Firefox
    #**C:\Program Files (x86)\Mozilla Firefox
    #Now, go ahead and reinstall Firefox:
    ##Double-click the downloaded installation file and go through the steps of the installation wizard.
    ##Once the wizard is finished, choose to directly open Firefox after clicking the Finish button.
    More information about reinstalling Firefox can be found [[Troubleshoot and diagnose Firefox problems#w_5-reinstall-firefox|here]].
    <b>WARNING:</b> Do not use a third party uninstaller as part of this process. Doing so could permanently delete your [[Profiles|Firefox profile]] data, including but not limited to, extensions, cache, cookies, bookmarks, personal settings and saved passwords. <u>These cannot be easily recovered unless they have been backed up to an external device!</u> See [[Back up and restore information in Firefox profiles]]. <!-- Starting in Firefox 31, the Firefox uninstaller no longer lets you remove user profile data.Ref: Bug 432017 and https://support.mozilla.org/kb/uninstall-firefox-from-your-computer/discuss/5279 [Fx31] Windows uninstaller will no longer offer the option to remove personal data -->
    Please report back to say if this helped you!
    Thank you.

  • After installing the safari update for windows outlook is not opening email links. I have set safari as my default browser but hyperlinks won't open a browser window - I get an error message - "This operation has been canceled due to restrictions in effec

    After installing the safari update for windows, outlook is now not opening email hyperlinks.  I have set safari to be my default browser but outlook won't open it when I click a link.  I get the following message: "This operation has been canceled due to restrictions in effect on this computer. Please contact your system administrator."  Please help.

    Hi mcclausky, you may need to manually remove a policy setting from the registry. You also should scan for malware that might have created this problem.
    This article lists scanning and cleaning tools other Firefox users have found helpful: [[Troubleshoot Firefox issues caused by malware]].
    To check your Windows registry for policy settings that might affect Firefox or other programs, I suggest consulting a Windows forum or Microsoft's forums. For example:
    * http://windowssecrets.com/forums/
    * [http://answers.microsoft.com/en-us/windows/forum/windows_8-system/this-operation-has-been-cancelled-due-to/9677848e-072d-4206-87f4-9da9284d6151 This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator. - Microsoft Community]
    * [http://answers.microsoft.com/en-us/windows/forum/windows_xp-security/restrictions-this-operation-has-been-cancelled-due/8af1d0cd-8fbd-4223-9396-86d7497bb275 Restrictions. This operation has been cancelled due to to restrictions in effect on this computer.Please contact your system administrator. - Microsoft Community]

  • Here we go again,....iTunes update for Windows 7 fails again same problem as back in Feb update

    Why is it that Apple is failing to get it right lately with their updates?
    Tried to install latest iTunes for Windows update on my PC Win 7 and it fails again wioth same error messages as with the previous update in Febr.
    Sooo very disappointed!!!!!
    To go thru all this again is taking me a few hours again to fix this problem assuming it works again this time, maybe I should just give up on iTunes instead.
    Troubleshooting issues with iTunes for Windows updates
    really *****,
    NE1 have any suggestions for an easy fix?
    thanks

    First off the automatic install fails nothing happens.
    Then tried the manual install after download, get the message that Apple mobile service failed to start and make sure i have required privileges to do so(Total BS)
    the SetupAdmin.exe file does not provide any action.
    Then right clicked the iTunes6464.msi file and installed it. Seems to install the update but when iTunes starts get the: "error 7" msg with iTunes helper was not installed correctly. Please reinstall iTunes. then w're in that **** loop......LOL
    I believe this is because I have a 4 yr old laptop with old graphic card.

  • I can,t install iTunes 11 for Windows   application failes to start because MSVCR80.dell was not found Windows 7

    I cant install itunes 11 for Windows 7, application fails because MSVCR80.dill is missing from my computer

    Hopefully this article will assist you:
    ≈≈≈≈≈≈≈≈
    http://support.apple.com/kb/TS5376
    ≈≈≈≈≈≈≈≈
    Please do reply with results/questions.

  • Intel Chipset Support for Windows 7 fails to install

    When I tried to manually install Intel Chipset Support for Windows 7, Vista and XP (oss907ww, Version: 9.1.1.1016, Release Date: 2009/10/02, http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-73684) on my W700 with Windows 7 x64, I got the following error message:
    "This computer does not meet the minimum requirements for installing the software. Setup will now exit."
    The newly released System Update 4.0 also fails to install this version of Intel Chipset Support. However, the previous version, Intel Chipset Support for Windows Vista, XP and 2000 (oss803ww, Version: 8.7.0.1007, Release Date: 2008/08/20, http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-70315) installs and works fine on my current system. Has anyone else had this problem?

    Hi,
    I have a problem installing the above mentioned chipset driver for win7. TVSU can't install it, and when I do it manually, it gives me a message saying (translated - original message was annoyingly in chinese) "This system does not meet the lowest requirements of the software. The installation will end now."
    I tried downloading it from lenovo's website, but it didn't work either, giving me the same message. The version of this driver is 9.1.1.1016 (according to TVSU).
    Anyone have any ideas on what on earth is wrong?
    Thank you all!
    Cassio
    Moderator note; subject edited to match thread
    T400s - 2815RW1 + Win7 Ultimate
    Don't pm me for help! That's what the forum is for. Also, Google's nicer than me. Ask him.

Maybe you are looking for

  • Is there any way to have a message sent at a specific time?

    Greetings: I am trying to figure out if there is a way to send an email to someone (not my own address) at a specific time on a specific date? Essentially I want to compose the email but only have it sent at midnight on December 1. Thanks in advance.

  • Handler chain file - validation files

    Hi Everyone, I have webservice where I would like to log all SOAP messages. Back in the WebLogic 8.1 days the developer merely specified an annotation to a soap handler like this: * @editor-info:link autogen-style="java" autogen="false" * @jws:handle

  • WIFI Icon Missing In Master Radio Control UI

    Okay, after putting up with this issue for a couple few months or so, I decided it's time to fix this issue... Well nothing seems to work, I've updated both drivers for the wireless LAN adapter. I also had an issue with Access Connections, so I updat

  • Error trying to authorize Bluefire reader

    I've just downloaded Bluefire reader to my iPad and I can't authorize my device.  I get the following error code. E_ACT_CERTIFICATION_SYNTAX I've used Bluefire in the past on this same iPad, but then deleted the app.  I didn't have this problem last

  • Set Default QT Export?

    I'm selecting various clips throughout my timeline to send to disk, is there a way to set the "File > Export > QuickTime Movie... > Setting" to something other than "Current Settings?" For instance, at the moment I'd like it to default to "ProRes 192