SSL Implementation Causes Password Reset and Registration Portals to Fail
I have successfully implemeted R2 and am able to get the password reset and registration working on my intranet. However, when I cahnge everything over to use SSL the portals fail. For example, when I go to either portal it takes me to the FIM Home page. I click on View All Site Content then under Users select Password Registration. This takes back to the FIM Home Page. Things I have done: Reran setup and in change mode and changed http to https ensured all related links are now https(SPN's, etc.) Changed the bindings for FIM primary page to use HTTPS and removed HTTP. Performed an IIs reset In other words followed exactly the instructions for FIM R2 for using SSL. Any ideas or questions?
June 28th, 2012 11:47am

I hope you did not change your SPN to https/serviceaccount the Service is still http/serviceaccount even though the protocol used is https. Also make sure the AAM in Sharepoint are changed to https://fimportal. And also... the FIM-Service url should still be http://fimservice:5725
Free Windows Admin Tool Kit Click here and download it now
June 28th, 2012 12:34pm

I think Kent's probably got it, but the one other thing that occurs to me to watch out for is that the change in the URL could put it into a different security zone in IE depending on how your Local Intranet zone is defined. Normally user logon information (Kerberos-style) is not automatically flowed to web sites except the Local Intranet zone. If this were your problem I'd expect different behavior than what you report, but I've seen stranger things. Chris
June 28th, 2012 2:29pm

I had the same problem. In my case it was the certificate used...Check after IISRESET, you will see that the home page cert is now applied to your password reset / registration sites... this is because of the URL in the cert I think... I followed this article http://technet.microsoft.com/en-us/library/hh322875(WS.10).aspx but instead of just listing the 2 password portals in the common name section, I listed all 3 sites... then used the certificate on all 3 sites. Since my deployment is only internal, with internal PKI certs being used, I didn't see the need to try and struggle too much with this... Hope this helps. Q
Free Windows Admin Tool Kit Click here and download it now
July 2nd, 2012 8:34am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics