nerdexam
Microsoft

70-649 · Question #23

Your network contains two servers named Server1 and Server2 that run Windows Server 2008 R2. Server1 has the Active Directory Federation Services (AD FS) Federation Service role service installed. You

The correct answer is D. Personal Information Exchange PKCS #12 (.pfx). Every federation server in an Active Directory Federation Services (ADFS) server farm must have access tothe private key of the token-signing certificate. If you are implementing a server farm of federation servers thatshare a single, exportable private key certificate that is is

enhanced security implementations

Question

Your network contains two servers named Server1 and Server2 that run Windows Server 2008 R2. Server1 has the Active Directory Federation Services (AD FS) Federation Service role service installed. You plan to deploy AD FS 2.0 on Server2. You need to export the token-signing certificate from Server1, and then import the certificate to Server2. Which format should you use to export the certificate?

Options

  • ABase-64 encoded X.509 (.cer)
  • BCryptographic Message Syntax Standard PKCS #7 (.p7b)
  • CDER encoded binary X.509 (.cer)
  • DPersonal Information Exchange PKCS #12 (.pfx)

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    11% (4)
  • C
    5% (2)
  • D
    81% (30)

Explanation

Every federation server in an Active Directory Federation Services (ADFS) server farm must have access tothe private key of the token-signing certificate. If you are implementing a server farm of federation servers thatshare a single, exportable private key certificate that is issued by an enterprise certification authority (CA), theprivate key portion of the existing token-signing certificate must be exported to make it available for importinginto the certificate store on the new

Topics

#AD FS#token-signing certificate#PKCS #12#certificate export

Community Discussion

No community discussion yet for this question.

Full 70-649 Practice