Repository navigation
Copy RSA Master Key to new ADFS farm #389
Replies: 3 comments 1 reply
|
Hi, One advantage is that you're positioning your disaster recovery platform on the same Active Directory forest. Where is the RSA encryption key located? It's not stored anywhere by MFA, but exists somewhere on your ADDS. It's crucial for the plugin that the MFA configuration is exactly the same as in production. You absolutely must have the same passphrase. Export the production configuration using Export-MFASystemConfiguration. Then modify the XML file to:
Then, import the modified configuration into the new farm Then you have to test |
|
Thank you, I'll give it a try and will report back. |
|
One more question to better understand the RSA key principle. You said "It's not stored anywhere by MFA, but exists somewhere on your ADDS". Which key is used and how get it generated in the first place? The key get generated by ADDS on its own and your plugin refers to it? |
Uh oh!
There was an error while loading. Please reload this page.
We are currently using your ADFS MFA plugin in our existing ADFS farm, with Active Directory configured as the storage backend.
As part of our disaster recovery strategy, we have now deployed an additional, independent ADFS farm within the same Active Directory domain. Our goal is to secure this DR ADFS farm using the same MFA plugin configuration and reuse the existing RSA master key. So I've a few questions:
All reactions