建立的第一個聯盟伺服器聯盟伺服器陣列Create the First Federation Server in a Federation Server Farm

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

您安裝同盟服務的角色,並在電腦上設定所需的憑證之後,您就可以設定電腦成為聯盟伺服器。After you install the Federation Service role service and configure the required certificates on a computer, you are ready to configure the computer to become a federation server. 您可以使用下列程序來設定電腦變得新聯盟伺服器陣列使用 AD FS 聯盟伺服器設定精靈中的第一個聯盟伺服器。You can use the following procedure to set up the computer to become the first federation server in a new federation server farm using the AD FS Federation Server Configuration Wizard.

建立的第一個聯盟伺服器發電廠中的動作也會建立新的同盟服務,並讓這台電腦的主要聯盟伺服器。The act of creating the first federation server in a farm also creates a new Federation Service and makes this computer the primary federation server. 這表示這部電腦,將會使用 AD FS 設定資料庫 read/寫入複本設定。This means that this computer will be configured with a read/write copy of the AD FS configuration database. 所有其他聯盟伺服器此必須複製將它們儲存在本機 AD FS 設定資料庫他們僅限 read\ 複本主要聯盟伺服器上所做的任何變更。All other federation servers in this farm must replicate any changes that are made on the primary federation server to their read-only copies of the AD FS configuration database that they store locally. 如需有關這個複寫程序,請查看的角色 AD FS 設定資料庫的For more information about this replication process, see The Role of the AD FS Configuration Database.

注意

聯盟網路 Single-Sign-On (SSO) 設計,您必須至少一個聯盟伺服器 account 合作夥伴組織和資源合作夥伴組織中的至少一個聯盟伺服器。For the Federated Web Single-Sign-On (SSO) design, you must have at least one federation server in the account partner organization and at least one federation server in the resource partner organization. 如需詳細資訊,請查看放置聯盟伺服器For more information, see Where to Place a Federation Server.

資格網域系統管理員」,或獲得寫入存取 Active Directory 中程式資料容器委派的核對最小,才能完成此程序。Membership in Domain Admins, or a delegated domain account that has been granted write access to the Program Data container in Active Directory, is the minimum required to complete this procedure.

若要建立的第一個聯盟伺服器聯盟伺服器陣列中To create the first federation server in a federation server farm

  1. 有兩種方法可以開始 AD FS 聯盟伺服器設定精靈。There are two ways to start the AD FS Federation Server Configuration Wizard. 若要開始精靈中,執行下列其中一個動作:To start the wizard, do one of the following:

    • 同盟服務角色服務安裝完成後,開放 AD FS 管理 snap\ 中,按一下AD FS 聯盟伺服器設定精靈上的連結概觀頁面或控制項窗格。After the Federation Service role service installation is complete, open the AD FS Management snap-in and click the AD FS Federation Server Configuration Wizard link on the Overview page or in the Actions pane.

    • 隨時之後安裝精靈完成,開放 Windows 檔案總管] 瀏覽至C:\Windows\ADFS資料夾,然後 double\ 按FsConfigWizard.exeAny time after the setup wizard is complete, open Windows Explorer, navigate to the C:\Windows\ADFS folder, and then double-click FsConfigWizard.exe.

  2. 歡迎頁面上,確認建立新的同盟服務已選取,然後按一下 [下一步On the Welcome page, verify that Create a new Federation Service is selected, and then click Next.

  3. 選取 Stand-只或發電廠部署頁面上,按一下 [新聯盟伺服器陣列,然後按一下 [下一步On the Select Stand-Alone or Farm Deployment page, click New federation server farm, and then click Next.

  4. 同盟服務名稱指定頁面上,確認SSL 憑證,會顯示正確。On the Specify the Federation Service Name page, verify that the SSL certificate that is showing is correct. 如果這不是正確的憑證,選取適當的憑證的SSL 憑證清單中。If this is not the correct certificate, select the appropriate certificate from the SSL certificate list.

    這個憑證也從安全通訊端層 (SSL) 設定為預設值的網站。This certificate is generated from the Secure Sockets Layer (SSL) settings for the Default Web Site. 如果只有一個 SSL 憑證設定預設值的網站,該憑證呈現及自動選取 [使用。If the Default Web Site has only one SSL certificate configured, that certificate is presented and automatically selected for use. 多個 SSL 憑證的網站,預設設定,如果以下列出這些所有憑證,您必須從他們中選取。If multiple SSL certificates are configured for the Default Web Site, all those certificates are listed here and you must select from among them. 不 SSL 設定為預設值的網站時,也可在本機電腦上的個人化的憑證存放區憑證的清單。If there are no SSL settings configured for the Default Web Site, the list is generated from the certificates that are available in the personal certificates store on the local computer.

    注意

    精靈將不允許您若 SSL 憑證已設定為 IIS 覆寫憑證。The wizard will not allow you to override the certificate if an SSL certificate is configured for IIS. 這樣可確保任何預期會保留先前 IIS 組態 SSL 憑證。This ensures that any intended prior IIS configuration for SSL certificates is preserved. 若要替代這項限制時,您可以移除憑證或重新手動 IIS Management Console 的設定。To work around this restriction, you can remove the certificate or reconfigure it manually with the IIS Management Console.

  5. 如果您已經選取 AD FS 資料庫存在,現有 AD FS 設定資料庫偵測到頁面隨即顯示。If the AD FS database that you selected already exists, the Existing AD FS Configuration Database Detected page appears. 是否出現該頁面,請按一下Delete 資料庫,然後按一下 [If that page appears, click Delete database, and then click Next.

    警告

    只有當您確定此 AD FS 資料庫中的資料並不重要或不使用正式作業聯盟伺服器陣列中,選取此選項。Select this option only when you are sure that the data in this AD FS database is not important or that it is not used in a production federation server farm.

  6. 指定服務帳號頁面上,按瀏覽]On the Specify a Service Account page, click Browse. 瀏覽對話方塊中,尋找網域帳號,做為服務中帳號這個新的聯盟伺服器發電廠,然後按一下 [ [確定]In the Browse dialog box, locate the domain account that will be used as the service account in this new federation server farm, and then click OK. 輸入密碼、確認,請然後按一下下一步Type the password for this account, confirm it, and then click Next.

    注意

    查看手動設定聯盟伺服器陣列服務 Account的詳細資訊指定聯盟伺服器陣列服務負責。See Manually Configure a Service Account for a Federation Server Farm for more information about specifying a service account for a federation server farm. 聯盟伺服器陣列中的每個聯盟伺服器必須指定相同服務負責發電廠才能正常運作。Each federation server in the federation server farm must specify the same service account for the farm to be operational. 例如,如果建立服務 account contoso\ADFS2SVC,聯盟伺服器角色您設定,並將參與相同發電廠每一部電腦必須 contoso\ADFS2SVC 此步驟,精靈中指定聯盟伺服器設定陣列才能正常運作。For example, if the service account that was created was contoso\ADFS2SVC, each computer that you configure for the federation server role and that will participate in the same farm must specify contoso\ADFS2SVC at this step in the Federation Server Configuration Wizard for the farm to be operational.

  7. 適用於設定準備頁面上,檢視詳細資料。On the Ready to Apply Settings page, review the details. 若出現正確設定,請按一下下一步來設定 AD FS 使用這些設定。If the settings appear to be correct, click Next to begin configuring AD FS with these settings.

  8. 設定結果頁面上,檢視結果。On the Configuration Results page, review the results. 所有的設定步驟完成時,按關閉以結束精靈。When all the configuration steps are finished, click Close to exit the wizard.

    重要

    基於安全部署,成品解析度並加以回覆偵測是當您使用 AD FS 聯盟伺服器設定精靈設定聯盟伺服器陣列停用。For secure deployment purposes, artifact resolution and reply detection are disabled when you use the AD FS Federation Server Configuration Wizard to configure a federation server farm. 精靈會自動設定 Windows 內部資料庫儲存服務設定資料。This wizard automatically configures the Windows Internal Database for storing service configuration data. 您可能會但是,誤復原這項變更,進而成品解析度端點使用的端點節點 snap\ 中 AD FS 管理或 Enable-ADFSEndpoint cmdlet Windows PowerShell 中的。You might, however, mistakenly undo this change by enabling the Artifact Resolution endpoint using either the Endpoints node in the AD FS Management snap-in or the Enable-ADFSEndpoint cmdlet in Windows PowerShell. 請務必重新使從此端點進行處於停用狀態,當您在一起使用聯盟伺服器陣列及 Windows 內部資料庫設定預設設定。Be careful to not reconfigure the default setting so that this endpoint remains disabled when you use a federation server farm and the Windows Internal Database together.

其他參考資料Additional references

檢查清單︰ 設定聯盟伺服器Checklist: Setting Up a Federation Server