Using BigFix Inventory SSL certificate for SSO based on SAML
From BigFix Inventory
11.0.3 new setups are using the BigFix Inventory SSL certificate for SSO. Earlier by default
up to version 11.0.3, a self-signed certificate is used during the SSO configuration.
However, you can reuse the BigFix Inventory server SSL certificate also in version before 11.0.3. This procedure
also applies when configuration was made before upgrading to the BigFix Inventory
11.0.3.
Procedure
- Navigate to the path install_dir\wlp\usr\servers\server1\server.xml.
-
Remove only
keyAlias="samlsp
andkeyStoreRef="SPKeyStore
from server.xml. - Open BigFix Inventory in a web browser.
-
Get the information about the certificate.
- Click on the Not secure label on the URL to display the window.
- Select the Certificate is not valid option above.
- Click on the Details tab.
- Export the certificate in base 64 encoded format.
-
Add the exported certificate to the Active Directory Federation Certificate
(ADFS).
- Navigate to ADFS management.
- Proceed to .
- Right-click on the available relying party and select Properties.
- Navigate to the encryption option.
- Remove the existing certificate.
- Click on Browse, and in the dropdown menu, select All Files.
- Upload the downloaded certificate.
- Restart the BigFix Inventory server.