ADFSToolkit-2.1.0
ADFSToolkit 2.1.0
Published and available on PowershellGallery.com as of May 19,2022
New Features
- New DLL for AD FS to enable recognition of REFEDS-MFA natively on AD FS with ADFSToolkit with source code
- Startup code for the module now triggers upon module loading for improved env handling (#25)
- Adopted use of Global settings for more flexibility in commands (#25)
Adjustments / Fixes
- Resolved metadata caching for improved accuracy on how SPs should refresh
- Resolved SP overlap detection and behaviour during initial deploys
- Resolved what to do when encountering Multiple SP’s with the same domain name by assigning a prefix separator
New Components / Commands
Core cmdlets:
- Install-ADFSTkMFAAdapter.ps1 - install REFEDS MFA support with new DLL and supporting settings
- Uninstall-ADFSTkMFAAdapter.ps1 - uninstall REFEDS MFA configuration
Auxiliary and helper cmdlets:
- Get-ADFSTkToolSpInfoFromMetadata.ps1 - fetch SP info from metadata (requires configuration in place)
- Remove-ADFSTkEntityHash.ps1 - assistant cmdlet to remove entity from cache
- Get-ADFSTkMFAAdapter.ps1 - checks for REFEDS MFA configuration
Upgrading
Consult https://github.com/fedtools/adfstoolkit/blob/master/doc/upgrade.md for details
Known Limitations
-
ADFSToolkit is designed for AD FS on Windows 2016 or newer. It may run on older instances but has not been tested.
-
ADFSToolkit has no known limitations itself and strives for full automation for loading a signed SAML2 aggregate. In order to accomplish this, ADFSToolkit attempts to make the 'best' choice for successfully loading an entity record under the conditions of the expected SAML2 R&E trust model.
Despite these best efforts ADFSToolkit lives in an imperfect world where there are observed limitations of Microsoft AD FS meeting SAML2 and Metadata handling practices enjoyed by other tools. There may be some cases where an AD FS Administrator may need to take one time action to allow a record they need to be loaded. In each case there is a way to handle the issue however we encourage Microsoft to improve support in this area and welcome dialog on how to improve these challenges outlined below:- AD FS' limitation of handling only one Relying Party encryption certificate per entity forces ADFSToolkit to choose the newest certificate as detected by certificate date it observes. This choice may conflict with how the RP decides to roll over certificates and require AD FS admin intervention to handle the rollover period more appropriately if this default is not the proper choice.
- AD FS' limitation of handling only a single signing certificate across all Relying Parties may require an AD FS Administrator to intervene to appropriately load the desired service on an ongoing basis via ADFSToolkit.
This is acutely experienced when multiple aggregates may be configured with entities in both. In this case, the first one loaded 'wins'.
Full Changelog: v2.0.1...v2.1.0