Tools
Export, import, and upload the token-signing certificate
This article describes how to export, import, and upload the token-signing certificate.
First published date
Last published date
Overview
This article describes how to export, import, and upload the token-signing certificate from the Microsoft® Active Directory Federation Services (AD FS) 2.0 server.
AD FS is installed in the Microsoft Windows Server® operating system to provide users with sign-on access to Windows systems and applications
See the Microsoft TechNet website (© Microsoft 2018, available at https://www.microsoft.com/en-us/, obtained on November 20, 2018) for more information about AD FS.
Product section
Resolution
- Export the token-signing certificate from the AD FS server.
- Import the certificate into the Web Help Desk trust store (cacerts).
- Upload the certificate into the Web Help Desk Admin Console.
Export the token-signing certificate from the AD FS server
- Open AD FS 2.0 and navigate to Service > Certificates.
Here, you will find the Token-signing certificate for your AD FS server that is used to authenticate your Security Assertion Markup Language (SAML) connection from Web Help Desk. - Click the Token-signing certificate.
- In the Actions section, click View Certificate.
- Click the Details tab, click Copy to File, and then click Next.
- Select Base-64 encoded X.509 (.CER), and click Next.
- Click Browse, select a location, enter a file name,, and then click Save.
Entering a new file name will not impact the setup.
- Click Next, and then click Finish.
- Copy the exported file to the Web Help Desk server.
Import the certificate into the Web Help Desk trust store (cacerts)
- Upload the certificate into the Web Help Desk Admin Console Stop Web Help Desk (Stop and start Web Help Desk).
- Open a Run dialog box and execute:
C:\Program Files\WebHelpDesk\Portecle.bat - Click File > Open Keystore file and navigate to:
C:\Program Files\WebhelpDesk\bin\jre\lib\security - Select All Files, select cacerts, and then click Open.
- Enter the following default password:
changeit
All common Certificate Authority (CA) certificates display in the file. - Select Tools > Import Trusted Certificates.
- Locate and select the exported file, and click Import.
If the Import Trusted Certificate window displays, click OK.
The exported certificate details display.
- Click OK, and then click Yes.
- Enter a certificate name alias that displays in the list of common CA certificates, and click OK.
The certificate alias does not affect the setup.
- Click OK.
The imported certificate displays in the list. - Select File > Save Keystore.
If you cannot save the file and an error message displays:- Open Portecle as an Administrator by navigating to the location of the Portecle.bat file.
- Right-click the file and select Run as Administrator.
- Start Web Help Desk (Stop and start Web Help Desk).
Upload the certificate into the Web Help Desk Admin Console
- Open a web browser and navigate to the Web Help Desk Admin Console.
- Log in to the console as an administrator.
- Click Setup > General > Authentication.
- Click the Authentication Method drop-down method and select SAML 2.0.
- Enter the sign-in page URL.
- Enter the Logout URL.
- Next to Verification certificate, click Upload.
- Locate and select the exported file, and then click Open.
- Click Save when the certificate is uploaded