Jorge's Quest For Knowledge!

All about Windows Server, ADDS, ADFS & ILM/FIM (It is just like an addiction, The more you have, the more you want to have!)

Archive for the ‘Forefront Identity Manager (FIM) Certificate Management’ Category

(2011-11-24) Forefront Identity Manager 2010 R2 Release Candidate Now Available

Posted by Jorge on 2011-11-24

Mark Wahl writes on the Microsoft Server and Cloud Platform Blog about the release and availability of Forefront Identity Manager 2010 R2.

-

SOURCE: Forefront Identity Manager 2010 R2 Release Candidate Now Available

-

<QUOTE SOURCE=”Forefront Identity Manager 2010 R2 Release Candidate Now Available>

Microsoft is pleased to announce the availability of Forefront Identity Manager 2010 R2 release candidate. It is available for download from Microsoft Connect, as described below.

This release candidate includes new and updated features for FIM 2010 R2:

  • Historical reporting using integration to the System Center Service Manager data warehouse
  • Web-based Self-Service Password Reset
  • Scale and performance improvements
  • Outlook® 2010 support for the FIM add-ins and extensions and SharePoint® 2010 support for the FIM Portal

In particular, this release candidate introduces numerous functional improvements, including:

  • New authentication gates for self-service password reset
  • Additional reports
  • Extensible Connectivity Management Agent 2

For complete information, see the Release Notes and feature-specific documents.

If you have already joined the FIM 2010 Community Evaluation Program or downloaded the beta, you can obtain FIM 2010 R2 RC from the FIM 2010 Connect web site. The downloads link is in the left column.

To join the program and download the software, click here. Once you answer the survey questions, the Connect site will auto-approve your access.

Thanks,

Mark Wahl

Principal Program Manager

</QUOTE SOURCE=”Forefront Identity Manager 2010 R2 Release Candidate Now Available>

-

Cheers,
Jorge
———————————————————————————————
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always evaluate/test yourself before using/implementing this!
* DISCLAIMER:
http://jorgequestforknowledge.wordpress.com/disclaimer/
———————————————————————————————
############### Jorge’s Quest For Knowledge #############
#########
http://JorgeQuestForKnowledge.wordpress.com/ ########
———————————————————————————————

Posted in Beta/RC Stuff, Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | Leave a Comment »

(2011-10-24) A Hotfix Rollup Package (Build 4.0.3594.2) Is Available For Forefront Identity Manager 2010

Posted by Jorge on 2011-10-24

This hotfix rollup package both resolves issues and also introduces new features. I have not tried myself yet, but I’m particularly interested in “issue 2” mentioned in the “Fixed Issues In Sets And Query”

-

SOURCE: http://support.microsoft.com/kb/2520954

-

Fixed issues in Workflow Engine

* Issue 1

Assume that you perform an operation that accesses the SQL database when the Microsoft SQL Server connection pooling feature is enabled in the FIM server. For example, you run a query or a request. If the operation times out for any reason, a future operation on the same thread may fail until that thread is removed from the SQL connection pool. An error message that resembles the following is displayed in the FIM Service Application event log, in the RequestStatusDetails property for a request, or in the WorkflowStatusDetails property of a workflow instance:

Cannot enlist in the transaction because a local transaction is in progress on the connection.

Additionally, the time stamp is the same as the time when the operation fails.

-

Fixed issues in Sync Engine

* Issue 1

An ExpectedRulesEntry (ERE) object is associated to a child synchronization rule of a Metaverse object. If the ERE object has a Remove action, deprovisioning of the object is also being triggered. Then, the behavior causes the deletion of the Metaverse object.

-

* Issue 2

Fixes an access violation when a custom extension calls a COM+ object.

-

* Issue 3

An earlier hotfix introduced a special Extensible Connectivity Management Agent (ECMA) mode to keep unconfirmed exports in escrow instead of awaiting confirmation. An issue with that hotfix causes delta sync to add new items that are not merged with an escrowed export into a pending export. After you install the hotfix that is mentioned in this article, if the ECMAAlwaysExportUnconfirmed registry entry is set to 1, the escrowed and pending changes are merged.

-

* Issue 4

Fixes an SQL query construction issue that occurs during an import. This issue affects a DB2 database that uses a non-Unicode character set.

-

* Issue 5

Fixes many "Export not reimported" errors that might occur because of errors in SQL.

-

* Issue 6

Improves the performance of all Sync Engine operations.

Note This change involves an extensive upgrade to the sync database. This upgrade can take lots of time, depending on your hardware. A progress bar is displayed during the database upgrade.

-

* Issue 7

A password reset that uses the ADMAEnforcePasswordPolicy registry setting fails when the user is in the Administrator group but is not an administrator.

-

* Feature 1

Adds an option to have FIM 2010 export the current time on the server to the HTTPPasswordChangeDate field during the password set operation. The time stamp is stored as a TimeDate data type.

To enable this behavior, set the following registry subkey to a nonzero DWORD Value: HKLM\

SYSTEM\CurrentControlSet\Services\FIMSynchronizationService\Parameters\NotesMAExportPwdTimestamp

-

* Feature 2

The FIM 2010 Active Directory Management Agent (AD MA) does not honor the preferred domain controller list when passwords are exported. This is an issue for customers who require password changes to flow to a specific set of domain controllers. This hotfix rollup package changes the AD MA to use the preferred domain controller list first. If the preferred domain controller list does not exist, the domain controller locator service will identify a domain controller for password export operations. Additionally, you can still force password operations to use the primary domain controller by setting the following registry subkey:

Subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FIMSynchronizationService\Parameters\PerMAInstance\<MA_name>

Value: UsePDCForPasswordOperations (REG_DWORD, 1 = True, 0 = False)

This hotfix rollup package also updates the AD MA so that a trust relationship with the configured Active Directory forest is not required to export passwords to that forest.

-

* Feature 3

Adds the ability to filter objects before they are imported into the AD MA connector space.

-

* Feature 4

Adds new options to the Storechk.exe tool to enable it to remove orphaned rule fragments that are associated with an MA. To do this, you can run the tool by using the following command-line options:

Storechk.exe -sync –repair

-

Fixed issues in Sets and Query

* Issue 1

Fixes an issue that would sometimes cause incorrect Set calculations. This resulted in lots of set corrections. Also revised the Sets Correction job so that it does not change special sets that are maintained by another system maintenance job.

-

* Issue 2

Revised the FIM "Query and Sets" features to treat underscores and percent signs as literals instead of as SQL wildcard characters.

-

Fixed issues in Certificate Management

* Issue 1

Enables the random number generator in the server key generation function.

-

* Issue 2

Improves the performance when enrolling a smartcard that has not previously been used with FIM Certificate Management (CM).

-

Fixed issues in FIM Management Agent (MA)

* Issue 1

Fixes an issue in which the FIM synchronization service configuration for synchronization rules and codeless provisioning was not correctly written to the FIM Service database.

-

Fixed issues in FIM Service

* Issue 1

Fixes an issue with SQL Server deadlocks that might occur during periods of high concurrency of requests or approvals.

-

* Issue 2

Fixes an issue in which unexpected data in the FIM Service database could result in the FIM MA causing the Synchronization service to fail during import, and a stopped-server error occurred.

-

* Issue 3

Fixes an issue when you add or remove a value for a multivalued string attribute. If the request was subject to authorization such as request reevaluation, the request would fail after approval.

-

* Issue 4

Some ExpectedRuleEntry objects and DetectedRuleEntry objects in FIM 2010 can become "orphaned" over time. When a DetectedRuleEntry object is not referenced in the DetectedRulesList of any object in the system, that object is determined to be orphaned. Similarly, when an ExpectedRuleEntry object is not referenced in the ExpectedRulesList of any object in the system, that object is also determined to be orphaned.

These orphaned objects have no functional impact on FIM. However, over time, these orphaned objects can cause a decrease in performance for both FIM operations and Sync operations that are related to FIM, such as import or export by using the FIM MA.

A pruning stored procedure, [debug].[DeleteOrphanedRulesByType], was added to the [debug] namespace of the FimService database. This stored procedure must be run separately for the DetectedRuleEntry object and the ExpectedRuleEntry object. The stored procedure also has a "reportOnly" mode, and this mode can be used to determine the presence and number of orphaned DetectedRuleEntry and ExpectedRuleEntry objects in the system.

The @ruleType parameter expects one of the following well-known values:

  • N’Detected’ for DetectedRuleEntry objects
  • N’Expected’ for ExpectedRuleEntry objects
  • -

    To determine the number of orphaned objects in the system, run the stored procedure in "reportOnly" mode as follows.

    DECLARE @deletedRulesFound BIT; EXEC [debug].[DeleteOrphanedRulesByType] @ruleType=N'CHANGE_ME', @reportOnly=1, @deletedRulesFound=@deletedRulesFound OUTPUT;

    -

    To loop through and actually delete orphaned objects in the system, run the stored procedure as follows. @deletionLimit=1000 instructs the procedure to stop when it has deleted 1,000 objects. If there are more than 1,000 orphaned objects in the system, either run the procedure multiple times (recommended) or increase the deletionLimit value.

    DECLARE @deletedRulesFound BIT, @startDateTime DATETIME, @endDateTime DATETIME; SELECT @deletedRulesFound = -1; WHILE @deletedRulesFound <> 0 BEGIN SELECT @startDateTime = CURRENT_TIMESTAMP; EXEC [debug].[DeleteOrphanedRulesByType] @ruleType=N'CHANGE_ME', @deletionLimit=1000, @reportOnly=0, @deletedRulesFound=@deletedRulesFound OUTPUT; SELECT @endDateTime = CURRENT_TIMESTAMP; SELECT @startDateTime AS [StartTime], @endDateTime AS [EndTime], @deletedRulesFound AS [WereDeletedRulesFound]; END

    -

    Cheers,

    Jorge

    ———————————————————————————————

    * This posting is provided "AS IS" with no warranties and confers no rights!

    * Always evaluate/test yourself before using/implementing this!

    * DISCLAIMER: http://jorgequestforknowledge.wordpress.com/disclaimer/

    ———————————————————————————————

    ############### Jorge’s Quest For Knowledge #############

    ######### http://JorgeQuestForKnowledge.wordpress.com/ ########

    ———————————————————————————————

     

    Posted in Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | Leave a Comment »

    (2011-02-18) Latest Rollup Hotfix Available For FIM 2010 (build 4.0.3573.2)

    Posted by Jorge on 2011-02-18

    A few weeks ago Microsoft released a new KB article MS-KBQ2417774 which included FIM 2010 build 4.0.03561.2. The first days of february that KB article was updated to release a new revision (revision 4) of that build. However it did get a new build number being build 4.0.03573.2. About a week ago, the KB article was updated again to release a newer revision (revision 5) of the latter build (build 4.0.03573.2). So we got an update for the update! :-) .

    When you compare the revision 4 build with the revision 5 build, the revision 5 build does not include updates for FIM CM and FIM PCNS. Weird, because revision 4 is not available anymore, only revision 5 build.

    In my opinion the most interesting updates in this new build are:

    • AD MA now fully supports AD Recycle Bin;
    • Approval operations can be processed by any FIM instance;
    • Improved FIM MA performance (multi-threaded), especially during initial loads

    For more details see, the link to the KB article is: A hotfix rollup package (build 4.0.3573.2) is available for Forefront Identity Manager 2010 (REV5)

    On my FIM 2010 test environment I already had deployed revision 4 and last night I updated it with revision 5 without any issues. I still need to test if everything I configured is still working. If something breaks, I’ll post it here.

    Ohhh, and to do too much at the same time I also decide to update my FIM 2010 test environment, based upon W2K8R2 and Win7, to SP1 which was released a few days ago.

     

    Cheers,
    Jorge
    ———————————————————————————————
    * This posting is provided "AS IS" with no warranties and confers no rights!
    * Always evaluate/test yourself before using/implementing this!
    * DISCLAIMER:
    http://jorgequestforknowledge.wordpress.com/disclaimer/
    ———————————————————————————————
    ############### Jorge’s Quest For Knowledge #############
    #########
    http://JorgeQuestForKnowledge.wordpress.com/ ########
    ———————————————————————————————

    Posted in Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | Leave a Comment »

    (2010-03-02) Forefront Identity Manager 2010 Has RTMed!

    Posted by Jorge on 2010-03-02

    Forefront Identity Manager 2010, ILM 2007 FP1′s successor, has RTMed! Finally! J

    Get the evaluation version here.

     

    Cheers,
    Jorge
    ———————————————————————————————
    * This posting is provided "AS IS" with no warranties and confers no rights!
    * Always evaluate/test yourself before using/implementing this!
    * DISCLAIMER:
    http://jorgequestforknowledge.wordpress.com/disclaimer/
    ———————————————————————————————
    ############### Jorge’s Quest For Knowledge #############
    #########
    http://JorgeQuestForKnowledge.wordpress.com/ ########
    ———————————————————————————————

    Posted in Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync, IT News | Leave a Comment »

    (2010-01-30) Update 3 Has Been Released For FIM 2010 RC1

    Posted by Jorge on 2010-01-30

    Microsoft has released Update 3 for FIM 2010 RC1. It is available connect here. This is the final pre-release of the product before RTM. I think this is a major release because it can be installed as an update or as a new install from scratch. It contains a (new) installation guide. Make sure to read the release notes FIRST before installing it!!!

    Summary of changes in Update 3

    This package contains multiple updates to the following Microsoft® Forefront™ Identity Manager 2010 feature areas. It also contains a number of general improvements to FIM functionality and reliability.

    • New prerequisites:
    1. Windows® Installer 4.5 for all server components
    2. For the FIM Service: Microsoft SQL Server® 2008 Service Pack 1 (SP1)
    3. For the FIM Add-In for Outlook: Microsoft Office Outlook® 2007 Service Pack 2 (SP2)
    • New supported platforms for FIM Certificate Management:
    1. Windows Server® 2008 R2
    2. Windows Server Datacenter Edition
    • FIM Synchronization Service improvements:
    1. Fixed customer-reported failures in FIM Synchronization Service.
    2. Fixed issues with multimastered attributes.
    3. The FIM management agent (MA) will now store error messages with the operation during export. You do not have to look in the FIM Service event log anymore to view the errors.
    4. You can now have several MAs that are responsible for deleting a resource. This solves a common problem in which custom code was necessary for Declarative provisioning.
    5. Added two new Declarative provisioning functions:
    6. Null – This SR should not contribute a value.
    7. ReplaceString – Find and replace a substring in another string.
    • Introduces new Management Policy Rule (MPR) types:
    1. The new Set Transition MPR type allows for easy creation of Policies that apply to Set membership changes (that is, when resources enter or leave a specific Set).
    2. During Update 3 installation, all existing MPRs in the system are marked as Request-based MPRs.
    3. The Run On Policy Update flag is now applicable only to the new Set Transition MPRs.
    4. Temporal policy definitions require the use of the new Set Transition MPRs.
    • Fixes an issue in which queries did not evaluate correctly if they contained three or more conditions and at least two of them used the not() operator.
    • Adds support for Exchange 2010, which includes the following:
    1. FIM Synchronization Service support for Active Directory MA and global address list (GAL) MA
    2. The FIM Service sending and receiving mail
    3. Outlook 2007 on Exchange 2010 sending approvals and group membership requests
    • Adds support for SQL Server Failover Clusters for High Availability.
    • Adds support for taking database backups without stopping the FIM Service.
    • Removes DomainSynchronizationActivity and replaces it with built-in logic to support cross-forest group management.

    Important

    This update deletes the WorkflowDefinition Group management workflow: Domain information synchronization for cross-forest resources, which has the Resource ID 955e3366-fbcc-43ee-b6e4-2001b81971da. You should back up any changes you may have made to this resource before installing the update and then re-create the functionality in a new activity.

     

    Cheers,
    Jorge
    ———————————————————————————————
    * This posting is provided "AS IS" with no warranties and confers no rights!
    * Always evaluate/test yourself before using/implementing this!
    * DISCLAIMER:
    http://jorgequestforknowledge.wordpress.com/disclaimer/
    ———————————————————————————————
    ############### Jorge’s Quest For Knowledge #############
    #########
    http://JorgeQuestForKnowledge.wordpress.com/ ########
    ———————————————————————————————

    Posted in Beta/RC Stuff, Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | Leave a Comment »

    (2009-12-08) Update Release For FIM 2010 RC1 (Update 2)

    Posted by Jorge on 2009-12-08

    Microsoft has released another update for FIM 2010 RC1. After a few days it will be available through Windows Update.

    This package contains multiple updates to the following FIM feature areas:

    • Sets
    • Setup
    • Codeless Provisioning
    • Management Policy Rules
    • Portal user interface
    • Schema
    • Self-service Password Reset
    • Synchronization engine
    • Workflow

    Detailed information about the updates mentioned can be read in the release notes for update2.

    Summary of changes in Update 2

    This package contains multiple updates to the following Microsoft® Forefront Identity Manager 2010 feature areas as well as a number of general improvements to functionality and reliability:

    • Codeless Provisioning
      • Adds a Null function to support not flowing values to a disabled AD account.
      • You can now set attribute precedence between classic provisioning and codeless provisioning attribute flows.
    • Configuration Migration Tool
      • During the import phase the Migration tool now resumes after logging failures. This allows the Migration tool to complete as many imports as possible on a single run while noting the failures still requiring administrator resolution.
      • Migrating custom resource types is now supported.
    • Management Policy Rules (MPR)
      • When defining permissions for enumeration you no longer need to grant all the permissions for required attributes as part of a single MPR. The system will now properly aggregate permissions from multiple MPRs when evaluating query permissions.
    • Password Reset
      • Password Reset now accepts the user principal name (UPN) as well as the fully qualified domain name (FQDN) when specifying user credentials.
    • Portal User Interface
      • You can now copy and paste a vertical list from Excel to the Resource Picker input box. This is especially useful for doing bulk Adds.
      • The UOC text box now lets you check uniqueness on Create operations using a custom XPATH statement that you provide.
      • Note
        • Uniqueness checking only works in Create mode, not in Edit mode. Attempting this in Edit mode may cause the check to be done when it’s not intended.
        • Fixes an issue introduced in Update 1 where the portal may show valid Active Directory security group memberships as invalid.
    • Schema
      • The product now enforces schema validation at the web services layer to disallow Required reference types.
    • Sets
      • All Sets restrictions noted in the RC1 Release Notes have been removed. In particular:
      • You no longer need to avoid the use of the following operators in set creation: <, <=, >, >=, endswith, startswith, nesting.
      • You are no longer limited to using only the literal = operator with multi-valued operators when creating sets.
      • You no longer need to avoid having explicit members in a set which has a defined filter.
    • Setup
      • Resolves a number of issues that occurred on a first-time installation of the RTM product. These changes are not visible in the installations of the Updates, but you will receive the benefits of these improvements on new installations of the RTM product.
    • Synchronization engine
      • Synchronization rule error messages are now visible during synchronization previews.
      • Resolved an issue where having multiple join and projection rules causes rule corruption on a full synchronization.
      • Removes management agent (MA) support for Exchange version 5.5 and Windows NT.
      • Various other improvements in synchronization preview.
    • Workflows
      • Owner-originated requests are now auto-approved.

    Available Updates….



    Component

    MSP Name

    FIM 2010 RC1 Synchronization Service (Evaluation edition–this is the version in the public download)

    FIMSyncService_EVAL_KB977312.msp

    FIM 2010 RC1 Synchronization Service (VL edition–this is the version for production deployments)

    FIMSyncService_VL_KB977312.msp

    FIM 2010 RC1 Service and Portal

    FIMService_KB977312.msp

    FIM 2010 RC1 Service and Portal Language Packs

    FIMServiceLP_KB977312.msp

    FIM 2010 RC1 Add-ins and Extensions (Note: versions included for x86 and x64)

    FIMAddinsExtensions_KB977312.msp

    FIM 2010 RC1 Add-ins and Extensions Language Pack (Note: versions included for x86 and x64)

    FIMAddinsExtensionsLP_KB977312.msp

    The EXEs cannot be used to directly install the update. If you try you will get the following error "This patch package could not be opened. Contact the application vendor to verify that this is a valid Windows Installer patch package"

    So, if it is an EXE, you can use either of the following methods:

    1. <File>.exe /C:"MSIEXEC /p <MSP File Name>"
      OR if that does not work
    2. <File>.exe /T:"<Folder to extract to>" –> if you get the error "", then do not click OK right away, but look in the folder. Copy the MSP to another location and then click OK.

    So, if it is a CAB, just extract it.

    Then double-click the MSP file to install it.

    Get this update here. (Windows Update Catalog)

    More info here. (may not be available right away, but rather later on!)

    Make sure to read the release notes about how to install!!!

    Cheers,
    Jorge
    ———————————————————————————————
    * This posting is provided "AS IS" with no warranties and confers no rights!
    * Always evaluate/test yourself before using/implementing this!
    * DISCLAIMER:
    http://jorgequestforknowledge.wordpress.com/disclaimer/
    ———————————————————————————————
    ############### Jorge’s Quest For Knowledge #############
    #########
    http://JorgeQuestForKnowledge.wordpress.com/ ########
    ———————————————————————————————

    Posted in Beta/RC Stuff, Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | 3 Comments »

    (2009-11-11) Installing The Update1 For FIM 2010 RC1

    Posted by Jorge on 2009-11-11

    As I mentioned a few days ago, Microsoft released an update (Update1) for FIM 2010 RC1. Read more about it here. The update basically consists of 4 components (Sync Engine, Service/Portal, Add-In Extension and Language Pack). If you install the update for the Sync Engine and you stop the FIM Synchronization Service, the update installs fine. Unfortunately the same is not true when installing the update for the FIM Service, especially in a certain scenario.

    If you have chosen a self-issued certificate during the installation of the service/portal, the update installs OK.

    If you have chosen to use a certificate assigned by some CA during the installation of the service/portal, then the installation of the update will fail! This can go both ways, meaning either Microsoft forgot to test the installation of the update when using a certificate assigned by some CA or Microsoft forgot to mention in the release notes the additional steps required to be able to successfully install the update for FM 2010 RC1.

    The following scenarios are possible:

    1. You still have NOT installed the FIM Service/Portal
    2. You already have installed the FIM Service/Portal and you used a self-issued certificate during installation of the FIM Service/Portal and you want to keep it like that
    3. You already have installed the FIM Service/Portal and you used a self-issued certificate during installation of the FIM Service/Portal, but you still want to use a certificate assigned by some CA
    4. You already have installed the FIM Service/Portal and you used a certificate assigned by some CA during installation of the FIM Service/Portal

    AD.1
    You are lucky! Even if you intend to use a certificate assigned by some CA, make sure to use a self-issued certificate during the installation of the FIM Service/Portal. Then install the update for the FIM Service. After that, use the following procedure to start using the certificate assigned by some CA.

    Extra Procedure

    1. From the certificate assigned by some CA get the value in the Thumbprint field. Remove all the spaces and replace lowercase letters with uppercase letters. The assumption here made is that the certificate assigned by some CA is already in the computer store
    2. Start REGEDIT
    3. Navigate to HKLM\SYSTEM\CurrentControlSet\Services\FimService
    4. Find the data field called "CertificateThumbprint" (REG_SZ)
    5. Replace the data value of that data field with the value from bullet 1 above
    6. Restart the FIM Service

    AD.2
    There is nothing to here, except for just installing the update

    AD.3
    Just install the update and afterwards use the following procedure

    Extra Procedure

    1. From the certificate assigned by some CA get the value in the Thumbprint field. Remove all the spaces and replace lowercase letters with uppercase letters. The assumption here made is that the certificate assigned by some CA is already in the computer store
    2. Start REGEDIT
    3. Navigate to HKLM\SYSTEM\CurrentControlSet\Services\FimService
    4. Find the data field called "CertificateThumbprint" (REG_SZ)
    5. Replace the data value of that data field with the value from bullet 1 above
    6. Restart the FIM Service

    AD.4
    You are not lucky. More additional steps are needed. Use the following procedure to be able to install the update.

    Extra Procedure

    1. Backup the FIMService DB using a FULL backup
    2. Start REGEDIT
    3. Navigate to HKLM\SYSTEM\CurrentControlSet\Services\FimService
    4. Find the data field called "CertificateThumbprint" (REG_SZ)
    5. Save the data value of that data field for future use. If you for whatever reason loose this value you can retrieve the value from the certificate assigned by some CA by getting the value in the Thumbprint field. Remove all the spaces and replace lowercase letters with uppercase letters. The assumption here made is that the certificate assigned by some CA is already in the computer store
    6. Uninstall the FIM Service/Portal
    7. Install the FIM Service/Portal and use the option "Re-use the existing database" and later on use the option "Generate a new Self-Issued Certificate"
    8. Install Update1 for FIM 2010 RC1
    9. Follow the steps in AD.3

    Cheers,
    Jorge
    ———————————————————————————————
    * This posting is provided "AS IS" with no warranties and confers no rights!
    * Always evaluate/test yourself before using/implementing this!
    * DISCLAIMER:
    http://jorgequestforknowledge.wordpress.com/disclaimer/
    ———————————————————————————————
    ############### Jorge’s Quest For Knowledge #############
    #########
    http://JorgeQuestForKnowledge.wordpress.com/ ########
    ———————————————————————————————

    Posted in Beta/RC Stuff, Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | 1 Comment »

    (2009-11-10) FIM 2010 RC1 VHD Is Available

    Posted by Jorge on 2009-11-10

    Microsoft made the VHD available for FIM 2010 RC1. Get it here.

    Cheers,
    Jorge
    ———————————————————————————————
    * This posting is provided "AS IS" with no warranties and confers no rights!
    * Always evaluate/test yourself before using/implementing this!
    * DISCLAIMER:
    http://jorgequestforknowledge.wordpress.com/disclaimer/
    ———————————————————————————————
    ############### Jorge’s Quest For Knowledge #############
    #########
    http://JorgeQuestForKnowledge.wordpress.com/ ########
    ———————————————————————————————

    Posted in Beta/RC Stuff, Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | Leave a Comment »

    (2009-11-08) Update Release For FIM 2010 RC1 (Update 1)

    Posted by Jorge on 2009-11-08

    Microsoft has released an update for FIM 2010 RC1 on the Microsoft Connect website. After a few days it will be available through Windows Update.

    This update addresses issues in the following FIM 2010 feature areas:

    • Management Policy Rules
    • Portal user interface
    • Query
    • Request Management
    • Self-service Password Reset
    • Schema
    • Sets
    • Synchronization engine
    • Workflows

    Get this update here.

    More info here.

    Cheers,
    Jorge
    ———————————————————————————————
    * This posting is provided "AS IS" with no warranties and confers no rights!
    * Always evaluate/test yourself before using/implementing this!
    * DISCLAIMER:
    http://jorgequestforknowledge.wordpress.com/disclaimer/
    ———————————————————————————————
    ############### Jorge’s Quest For Knowledge #############
    #########
    http://JorgeQuestForKnowledge.wordpress.com/ ########
    ———————————————————————————————

    Posted in Beta/RC Stuff, Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | 1 Comment »

    (2009-09-30) Forefront Identity Manager 2010 RC1 Is OUT!!!

    Posted by Jorge on 2009-09-30

    Remember RC0? Forget that!

    Microsoft has released Forefront Identity Manager (FIM) 2010 RC1 to the public.

    Wanna have it?

    Get it here. Make those servers suffer! J

    Documentation can be found here.

     

    Cheers,
    Jorge
    ———————————————————————————————
    * This posting is provided "AS IS" with no warranties and confers no rights!
    * Always evaluate/test yourself before using/implementing this!
    * DISCLAIMER:
    http://jorgequestforknowledge.wordpress.com/disclaimer/
    ———————————————————————————————
    ############### Jorge’s Quest For Knowledge #############
    #########
    http://JorgeQuestForKnowledge.wordpress.com/ ########
    ———————————————————————————————

    Posted in Beta/RC Stuff, Forefront Identity Manager (FIM) Certificate Management, Forefront Identity Manager (FIM) Portal, Forefront Identity Manager (FIM) Sync | Leave a Comment »