在身份验证站点与管理门户之间重新建立信任关系

 

适用于:Windows Azure Pack

从 Windows Azure Pack 部署中的任一虚拟机运行以下脚本一次。 有关重新建立信任的详细信息,请参阅 Windows Azure Pack 中的重新配置 FQDN 和端口

$MgmtStoreConnectionString="Data Source=$server;Initial Catalog=Microsoft.MgmtSvc.Store;User Id=sa;Password=$password"
$ConnectionString="Data Source=$server;User Id=$userid;Password=$password"
$TenantMetadataEndpoint="https://${AuthSiteLB}:$AuthSitePort/federationMetaData/2007-06/FederationMetadata.xml"
$AdminMetadataEndpoint="https://${WinAuthSiteLB}:$WinAuthSitePort/federationMetaData/2007-06/FederationMetadata.xml"

Set-MgmtSvcRelyingPartySettings -Target Tenant –MetadataEndpoint $TenantMetadataEndpoint  -DisableCertificateValidation -PortalConnectionString $PortalconnectionString  -ManagementConnectionString $MgmtStoreConnectionString
Set-MgmtSvcRelyingPartySettings -Target Admin –MetadataEndpoint $AdminMetadataEndpoint  -DisableCertificateValidation -PortalConnectionString $PortalconnectionString  -ManagementConnectionString $MgmtStoreConnectionString

$AdminSiteMetadataEndpoint="https://${AdminSiteLB}:$AdminSitePort/federationMetaData/2007-06/FederationMetadata.xml"
$TenantSiteMetadataEndpoint="https://${TenantSiteLB}:$TenantSitePort/federationMetaData/2007-06/FederationMetadata.xml"

Set-MgmtSvcIdentityProviderSettings -Target MemberShip –MetadataEndpoint  $TenantSiteMetadataEndpoint -ConnectionString $ConnectionString -DisableCertificateValidation
Set-MgmtSvcIdentityProviderSettings -Target Windows –MetadataEndpoint  $AdminSiteMetadataEndpoint -ConnectionString $ConnectionString -DisableCertificateValidation