{"id":1555,"date":"2016-07-05T09:36:41","date_gmt":"2016-07-05T09:36:41","guid":{"rendered":"http:\/\/neu.koetzingit.de\/xenmobile-und-adfs-als-dual-idp-fuer-sharefile-sso\/"},"modified":"2026-06-02T13:33:16","modified_gmt":"2026-06-02T13:33:16","slug":"xenmobile-und-adfs-als-dual-idp-fuer-sharefile-sso","status":"publish","type":"post","link":"https:\/\/www.koetzingit.de\/en\/xenmobile-und-adfs-als-dual-idp-fuer-sharefile-sso\/","title":{"rendered":"XenMobile and ADFS as dual IdPs for ShareFile SSO"},"content":{"rendered":"<p><span class=\"dropcapmiddle\">E<\/span>An Identity Provider (IdP) is required for ShareFile Enterprise, and Microsoft Active Directory Federation Service (ADFS) is often used as the IdP for this purpose. ShareFile and XenMobile work seamlessly together when XenMobile is used as the IdP. However, this would not allow for seamless integration with Windows clients that use the Outlook plug-in, Desktop Sync, etc. <strong>The solution is to use both IdPs<\/strong> at the same time, which is why it\u2019s called DualIdP. With ADFS 2.0, the certificate (self-signed by ADFS) cannot be exported with a private key for signing so that it can be used with XenMobile. Even if it could, this would only be valid for one year before ADFS automatically generates a new self-signed certificate.<\/p>\n<p><!--more--><\/p>\n<p>Citrix has an excellent document that explains how DualIdP works with XenMobile and ADFS (<a href=\"https:\/\/citrix.sharefile.com\/share\/view\/s710981789344434b\" target=\"_blank\" rel=\"noopener noreferrer\">Configure ADFS and XenMobile as a dual identity provider<\/a>) can be set up. However, I don\u2019t want to bore anyone here, so I might enhance the document with a few screenshots. I have used the document myself, and in my opinion, there are a few things to add and one error to correct. What you should do is read my comments and use them along with the document to ensure a successful setup.<\/p>\n<h3><span class=\"label label-success\">Comments on the document<\/span><\/h3>\n<ol>\n<li>Site 3 reads: \u201ePEM Encoding Algorithm \u2013 Drop down to <strong>DES<\/strong>\u201e.\u00a0<br \/>Even with DES and a 2048-bit key size, the resulting private key will only be 2036 bits long, and it won't work with ADFS. That is simply incorrect. You must <strong>DES3 <\/strong>for the\u00a0<strong>PEM Encoding Algorithm<\/strong> Select this option so that the key size is set to 2048.\n<\/li>\n<li>On page 7, it says: \u201eRun PowerShell as an administrator on the ADFS server. Type: Get-ADFSProperties\u201c<br \/>This won't work unless the ADFS cmdlets are loaded first. To load the cmdlets, run the following command in PowerShell: \u201e<strong>Add-PSSnapin Microsoft.Adfs.PowerShell<\/strong>\u201e\n<\/li>\n<li>After you finish the ADFS section and restart the ADFS service, it might not work! You may find the following in the ADFS event log: <strong>Event 133,<\/strong> which reads: \u201e<span lang=\"DE\">The private key for the certificate that was configured <strong>could not be accessed<\/strong>.\u201cThis is clearly a permissions issue with the ADFS service account when accessing the certificate for signing.\u201d. <br \/>Make a note of the account used for the ADFS service, such as a network service or a specific user account used during the ADFS setup. Then follow the instructions: \u201e<strong>Verify that the AD FS 2.0 service user account has access to the private keys for the certificates<\/strong>\u201c from the TechNet article <a href=\"https:\/\/technet.microsoft.com\/de-de\/library\/adfs2-troubleshooting-things-to-check(v=ws.10).aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Things to Check Before Troubleshooting AD FS 2.0<\/a>\u00a0to grant the account permissions to access the certificate. Then restart the ADFS service.\n<p><\/span><\/li>\n<li style=\"text-align: left;\"><span lang=\"DE\">On the last page: Logout URL: Logout URL to ADFS, e.g. <a href=\"https:\/\/adfs.company.com\/adfs\/ls\/?wa=wsignout1.0\">https:\/\/adfs.company.com\/adfs\/ls\/?wa=wsignout1.0<\/a> (<strong>This will need to be added as a logout point in ADFS if it hasn't been done already<\/strong>).<br \/><\/span>It is essential to follow this brief note; otherwise, you will receive an error message when logging out of ShareFile. To add the logout endpoint, go to the \u201eRelying Party Trust\u201c settings and select \u201eEndpoints.\u201c There, create a new \"SAML Logout\" endpoint.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1554\" style=\"margin-right: auto; margin-left: auto; display: block;\" src=\"http:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/adfs_logout_endpoint.png\" alt=\"Adfs Logout Endpoint\" width=\"401\" height=\"517\"  title=\"XenMobile and ADFS as dual IdPs for ShareFile SSO\" srcset=\"https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/adfs_logout_endpoint.png 401w, https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/adfs_logout_endpoint-233x300.png 233w\" sizes=\"auto, (max-width: 401px) 100vw, 401px\" \/><\/p>\n<p>\u00a0<\/p>\n<p>I hope this helps you successfully set up DualIdP with XenMobile and ADFS.\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>Ein Identity Provider (IdP) ist was mit ShareFile Enterprise ben\u00f6tigt wird und oft wird hierf\u00fcr Microsoft Active Directory Federation Service [&hellip;]<\/p>\n","protected":false},"author":1755,"featured_media":1553,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[26],"tags":[115,108,27,110,112,111,114,106,39,107,109,103],"class_list":["post-1555","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-xenmobile-de","tag-account","tag-adfs","tag-citrix","tag-dual","tag-event","tag-idp","tag-permission","tag-posh","tag-services","tag-sharefile","tag-sso","tag-xenmobile"],"uagb_featured_image_src":{"full":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/dual_idp.png",412,412,false],"thumbnail":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/dual_idp-150x150.png",150,150,true],"medium":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/dual_idp-300x300.png",300,300,true],"medium_large":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/dual_idp.png",412,412,false],"large":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/dual_idp.png",412,412,false],"1536x1536":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/dual_idp.png",412,412,false],"2048x2048":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/dual_idp.png",412,412,false],"trp-custom-language-flag":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2016\/07\/dual_idp.png",12,12,false]},"uagb_author_info":{"display_name":"Thomas K\u00f6tzing","author_link":"https:\/\/www.koetzingit.de\/en\/author\/thomas-koetzing\/"},"uagb_comment_info":0,"uagb_excerpt":"Ein Identity Provider (IdP) ist was mit ShareFile Enterprise ben\u00f6tigt wird und oft wird hierf\u00fcr Microsoft Active Directory Federation Service [&hellip;]","_links":{"self":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/users\/1755"}],"replies":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/comments?post=1555"}],"version-history":[{"count":1,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1555\/revisions"}],"predecessor-version":[{"id":1897,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1555\/revisions\/1897"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/media\/1553"}],"wp:attachment":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/media?parent=1555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/categories?post=1555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/tags?post=1555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}