locked
Cannot load Federation metadata URL RRS feed

  • Question

  • I am doing an IFD for a client and have followed a number of IFD guides.  Youtube videos, Microsoft's Implementation guide and another IFD Video from Microsoft.  All are different in how to successfully set up CRM for IFD.  I have CRM installed on a server separate from ADFS 2.0.  I have gotten as far as generating and binding certs to both the ADFS site and CRM sites.  When I reach the step of trying to verify the Federation services metadata, I am unable to load the xml.  This of course means that my ADFS box is not resolving in DNS, does it not?  Can anyone give me troubleshoot this error?  Any sources/recommendations for straight-forward guides for IFD?  Thanks!
    Wednesday, July 11, 2012 5:13 PM

Answers

  • Are you verifying the URL works in the browser? Are you getting an actual error? 

    For what its worth, when verifying the URL (https://sts.yourdomain.com/federationmetadata/2007-06/federationmetadata.xml) in IE I've seen a blank screen but was able to see the XML by switching the Compatibility View.


    Jason Lattimer

    • Marked as answer by wikky2007 Thursday, July 12, 2012 6:07 PM
    Thursday, July 12, 2012 2:13 AM
    Moderator

All replies

  • Are you verifying the URL works in the browser? Are you getting an actual error? 

    For what its worth, when verifying the URL (https://sts.yourdomain.com/federationmetadata/2007-06/federationmetadata.xml) in IE I've seen a blank screen but was able to see the XML by switching the Compatibility View.


    Jason Lattimer

    • Marked as answer by wikky2007 Thursday, July 12, 2012 6:07 PM
    Thursday, July 12, 2012 2:13 AM
    Moderator
  • It may be a DNS issue but you should be able to use nslookup to test that fairly easily.

    Did you install ADFS on port 443? Did you install it one port and then change the binding in IIS to another (which would not reset the reserved URLs)?

    Note the document "Microsoft Dynamics CRM 2011 and Claims-based Authentication.docx" has recently been updated so you may find slightly better information in this than previous versions:

    CRM 2011 Implementation, Planning and ADFS guides


    Hope this helps. Adam Vero, Microsoft Certified Trainer | Microsoft Community Contributor 2011

    Thursday, July 12, 2012 12:09 PM
  • JLattimer--The error I originally got (I have tried this a couple times now) was the red certificate error page. When I clicked "Continue to page anyway", it prompted me to save the federation data xml file.  When I tried to save it, it fails.  No loading of the xml within the browser took place.

    Adam--I have a CRM server and an ADFS server (as was dictated as best practice in MSDN documentation).  I installed ADFS on its own server since it uses the Default Web Site in IIS.  I bound the security cert to the default web site and then began the configuration of ADFS.  ADFS detects the cert from IIS no problem so I continued with the configuration until it completed successfully.  I have used a combination of guides to try and gauge the best way to do this.  Here are the guides:

    Microsoft Implementation Guide (IG) (the doc you mentioned)
    http://www.youtube.com/watch?v=T9jZIxDTsBw
    http://www.youtube.com/watch?v=ZD5qaa-G99E
    Implementing Claims-based Authentication and IFD video from Microsoft Partnersource

    I will download and look at the updated IG that you mentioned and try and see if it provides further insight.  Any other ideas?

    Thursday, July 12, 2012 1:44 PM
  • Clicking the Compatability View button showed the metadata.  Thanks!

    Thursday, July 12, 2012 6:08 PM