Answered by:
CRM 2011 IFD install

Question
-
Is it a requirement to use the Claims based authentication with IFD? Also, using ADFS 2.0?
If so, is it good practice to just install ADFS 2.0 on the same front end CRM server?
Thanks in advance!
Friday, July 8, 2011 7:45 PM
Answers
-
ADFS 2.0 and Claims-based auth are both requirements for IFD in CRM 2011.
It is generally best to not install ADFS on the same server because people have problems them utilizing port 443 for SSL on that server if ADFS is also on the server.
Jamie Miley
Check out my about.me profile!
http://mileyja.blogspot.com
Linked-In Profile
Follow Me on Twitter!- Proposed as answer by Jamie MileyModerator Friday, July 8, 2011 8:18 PM
- Marked as answer by Jamie MileyModerator Wednesday, February 15, 2012 5:45 PM
Friday, July 8, 2011 8:18 PMModerator -
Hi,
You may use wild card certficate (recommended) as it supports internal and external access requirements for a single domain. For example, *.contoso.com certificate supports the externally accessed domains org1.contoso.com and org2.contoso.com as well as the internally accessed domain internalcrm.contoso.com. Because the external domain name must resolve for internal access, you cannot use the server name for internal access. If you wish, you can use separate Microsoft Dynamics CRM Server 2011 servers for internal and external claims access to allow the server name to be used for internal access.
You may also use Internal Certicate authority which is recommended only for testing purposes. If you use a , it must be imported into the Trusted Root Certification Authorities store of all Microsoft Dynamics CRM Server 2011 servers and client computers accessing Microsoft Dynamics CRM Server 2011.
For certficate seleciton further queries you may also refer: http://technet.microsoft.com/en-us/library/gg188582.aspx
I would suggest you to reffer the followung links for proper step by step configuraiton guide:
http://blogs.msdn.com/b/crm/archive/2011/01/13/configuring-ifd-with-microsoft-dynamics-crm-2011.aspx
http://www.youtube.com/watch?v=T9jZIxDTsBw
http://dynamics-crm2011.blogspot.com/2011/05/crm-2011-adfs-20-federating-with-adfs.html
Jehanzeb Javeed
http://worldofdynamics.blogspot.com
Linked-In Profile |CodePlex Profile
If you find this post helpful then please "Vote as Helpful" and "Mark As Answer".
- Proposed as answer by Jehanzeb.Javeed Friday, July 8, 2011 11:10 PM
- Marked as answer by Jamie MileyModerator Wednesday, February 15, 2012 5:44 PM
Friday, July 8, 2011 11:01 PM
All replies
-
ADFS 2.0 and Claims-based auth are both requirements for IFD in CRM 2011.
It is generally best to not install ADFS on the same server because people have problems them utilizing port 443 for SSL on that server if ADFS is also on the server.
Jamie Miley
Check out my about.me profile!
http://mileyja.blogspot.com
Linked-In Profile
Follow Me on Twitter!- Proposed as answer by Jamie MileyModerator Friday, July 8, 2011 8:18 PM
- Marked as answer by Jamie MileyModerator Wednesday, February 15, 2012 5:45 PM
Friday, July 8, 2011 8:18 PMModerator -
Great, thanks. Also, I am definitely new to this authentication, but is there something with 'dummied down' configuration steps for it? Also, do I use both an internal certificate authority as well as a wildcard?
Friday, July 8, 2011 10:53 PM -
Hi,
You may use wild card certficate (recommended) as it supports internal and external access requirements for a single domain. For example, *.contoso.com certificate supports the externally accessed domains org1.contoso.com and org2.contoso.com as well as the internally accessed domain internalcrm.contoso.com. Because the external domain name must resolve for internal access, you cannot use the server name for internal access. If you wish, you can use separate Microsoft Dynamics CRM Server 2011 servers for internal and external claims access to allow the server name to be used for internal access.
You may also use Internal Certicate authority which is recommended only for testing purposes. If you use a , it must be imported into the Trusted Root Certification Authorities store of all Microsoft Dynamics CRM Server 2011 servers and client computers accessing Microsoft Dynamics CRM Server 2011.
For certficate seleciton further queries you may also refer: http://technet.microsoft.com/en-us/library/gg188582.aspx
I would suggest you to reffer the followung links for proper step by step configuraiton guide:
http://blogs.msdn.com/b/crm/archive/2011/01/13/configuring-ifd-with-microsoft-dynamics-crm-2011.aspx
http://www.youtube.com/watch?v=T9jZIxDTsBw
http://dynamics-crm2011.blogspot.com/2011/05/crm-2011-adfs-20-federating-with-adfs.html
Jehanzeb Javeed
http://worldofdynamics.blogspot.com
Linked-In Profile |CodePlex Profile
If you find this post helpful then please "Vote as Helpful" and "Mark As Answer".
- Proposed as answer by Jehanzeb.Javeed Friday, July 8, 2011 11:10 PM
- Marked as answer by Jamie MileyModerator Wednesday, February 15, 2012 5:44 PM
Friday, July 8, 2011 11:01 PM -
Great, thanks
Saturday, July 9, 2011 2:25 AM -
Hi,
I am glad that it helps, please Vote as Helpful and Mark as Answer to the threads :-)
Jehanzeb Javeed
http://worldofdynamics.blogspot.com
Linked-In Profile |CodePlex Profile
If you find this post helpful then please "Vote as Helpful" and "Mark As Answer".- Proposed as answer by VorisekTech Thursday, January 26, 2012 3:47 PM
Saturday, July 9, 2011 8:59 AM