The Dynamics CRM server may cache the signing certificate, which can cause trust errors when changing the PingFederate signing certificate. Reconfiguring claims-based authentication is recommended when you change the PingFederate signing certificate. After changing the signing certificate in the Dynamics CRM connection, do the following in the Dynamics CRM server:
  1. In the Microsoft Dynamics CRM Deployment Manager, disable claims-based authentication.
  2. Run iisreset from the command line on the Dynamics CRM Web server.
  3. In the Microsoft Dynamics CRM Deployment Manager, reconfigure claims-based authentication.
  4. In the Microsoft Dynamics CRM Deployment Manager, if previously enabled, reconfigure Internet-Facing Deployment.
  5. Run iisreset from the command line on the Dynamics CRM Web server.