question

RyanKohn-8055 avatar image
0 Votes"
RyanKohn-8055 asked KyleXu-MSFT commented

Exchange Delegation Federation Certificate Expired

We have a Federation Certificate that has expired on Sept 8th, 2021. I'm assuming if it expired, something would be broke? But, I, nor anyone else has seen any issues or reported any. Is there another certificate that it may possibly be using? From what I understand, this is for calendar free/busy. This was all set up by an employee who is not with us anymore and when we switched to Hybrid environment. Also, when going through Microsoft documentation on renewing an expired certificate, it says that one has to remove the trust and add it back. Isn't it possible to just add a new cert and assign the federation service to it? Sorry for the questions, but I am kind of lost. Thank you for any help! Much appreciated!

Ryan Kohn135651-27-09-2021-12-42-certificates-microsoft-exchange.jpg


office-exchange-hybrid-itpro
· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@RyanKohn-8055

I am writing here to confirm with you any update about this thread now?
If you renew this certificate successfully, please be free to mark it as an answer for helping more people.

0 Votes 0 ·

No, I have not renewed the certificate yet. I will update when I get that done.

0 Votes 0 ·

Can you renew the certificate successfully? If you get error when renew certificate, you could post it at here. We will help you narrow down it.

0 Votes 0 ·

1 Answer

Taz-3478 avatar image
0 Votes"
Taz-3478 answered RyanKohn-8055 commented

Hello @RyanKohn-8055!

Hope you are having a great day!

Thank you for asking a Question! We are Glad to Assist you!.

If the federation certificate has already expired, you need to remove all federated domains from the federation trust, and then remove and recreate the federation trust.
I am afraid, in your situation you will have to remove it and get it repalced.

Please go through the link mentioned below inorder to remove a federation trust.
https://docs.microsoft.com/en-us/exchange/remove-a-federation-trust-exchange-2013-help


After you have removed the Federation Trust, Visit the link mentioned below which explains how to renew the Federation Certificate :-
https://docs.microsoft.com/en-us/exchange/renew-the-federation-certificate-exchange-2013-help



Let me know if the above solution resolved your issue!



Regards,
Tasadduq Burney






|- Please don't forget to "Upvote" and "Accept as answer" if the reply is helpful -|



· 7
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Will this have any user impact? Also, would you know why we are not experiencing any issues with it being expired?

Thank you

0 Votes 0 ·

Hi Ryan!

As for the known user impact, it is as follows

  • Users Get an error when trying to search in Outlook.

  • Users get error when they try to Sync their calendar.

Federation Cert and throw an error if one doesn't exist.
Example: https://techcommunity.microsoft.com/t5/exchange-team-blog/how-to-address-federation-trust-issues-in-hybrid-configuration/ba-p/1144285

Use of Certificate :-
he reason for needing to re-create the trust is due to the fact that the federation certificate is used to authenticate any changes to the federation – so once it expires you can’t make any changes and have to start from scratch.



0 Votes 0 ·

Thank you very much for the explanation! I'll try to recreate sometime after hours. I appreciate it!

Ryan Kohn

0 Votes 0 ·

If you aren't in hybrid mode, then you probably wouldnt see any issues

0 Votes 0 ·

We are in Hybrid mode but still not seeing any issues.

0 Votes 0 ·
Show more comments