<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use the Web adapter with AWS Certificate Manager? in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511393#M19889</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the easiest thing to do is use&amp;nbsp;an AWS ALB as a pass-through to your Web Adapter host and let the ALB manage the SSL.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Nov 2018 22:30:52 GMT</pubDate>
    <dc:creator>JacobBoyle412</dc:creator>
    <dc:date>2018-11-09T22:30:52Z</dc:date>
    <item>
      <title>Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511392#M19888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use SSL certificates from AWS Certificate Manager. These certificates are not downloaded as files and deployed on the servers like other SSL's. We use them with AWS Elastic Load Balancers (ELB). We use the ELB's in place of the ArcGIS Web Adapter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am now planning a deployment of Portal. My deployment will require using the ArcGIS Web Adapter to support Roads &amp;amp; Highways. I'm curious if there is a way to continue using my AWS SSL's and&amp;nbsp;ELB's&amp;nbsp;&lt;SPAN style="text-decoration: underline;"&gt;as well as&lt;/SPAN&gt; the Web Adapter? If not, I imagine I will have to go buy an SSL certificate from a different provider to put on my Portal machine.&amp;nbsp;Thoughts about AWS ELB's and the ArcGIS Web Adapter co-existing?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mike S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2018 14:43:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511392#M19888</guid>
      <dc:creator>MikeSchonlau</dc:creator>
      <dc:date>2018-11-09T14:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511393#M19889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the easiest thing to do is use&amp;nbsp;an AWS ALB as a pass-through to your Web Adapter host and let the ALB manage the SSL.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2018 22:30:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511393#M19889</guid>
      <dc:creator>JacobBoyle412</dc:creator>
      <dc:date>2018-11-09T22:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511394#M19890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been tinkering with this, but without success. I'm not sure which port(s) the load balancer should be forwarding to. I thought 443 because the Web Adaptor is forwarding to 7443.&amp;nbsp;And would I add my EC2 instance to my target group over 443 or 7443? Or would I add the Web Adaptor url over 443 to the target group? Any thoughts on this would be appreciated. Thanks&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 05:33:14 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511394#M19890</guid>
      <dc:creator>MikeSchonlau</dc:creator>
      <dc:date>2018-11-16T05:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511395#M19891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The load balancer (ALB) should forward to the Web Adapter over 443, then the Web Adapter should take over from there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now, on the ALB settings in AWS Console under EC2, click load balancers, click your load balancer, click listeners. Then under Rules, click the rule for 443(80 may be the same rule), click the Health Checks tab, and confirm the following rules are set for ArcGIS Server and Portal for ArcGIS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Portal:&amp;nbsp;&amp;lt;Your_Context&amp;gt;/portaladmin/healthCheck&lt;/P&gt;&lt;P&gt;ArcGIS Server:&amp;nbsp; &lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN&gt;Y&lt;/SPAN&gt;&lt;SPAN&gt;our_Context&amp;gt;&lt;/SPAN&gt;/rest/info/healthCheck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 18:17:31 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511395#M19891</guid>
      <dc:creator>JacobBoyle412</dc:creator>
      <dc:date>2018-11-19T18:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511396#M19892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the feedback, Jacob.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My test&amp;nbsp;setup was very similar to your suggestion, except for my health check url. When I go to my Portal sign in page from an external ip or domain name, I keep getting this redirect error.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.esri.com/legacyfs/online/429925_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My load balancer has listeners for 80 and 443, both forwarding to a target group that is pointing to &lt;SPAN style="background-color: #ffffff;"&gt;my Portal health check url over https (443). My target is healthy. I can reach the Web Adaptor - Portal endpoint from the server itself using machine name, private ip, and localhost. When I try to reach the &lt;SPAN&gt;Web Adaptor -&amp;nbsp;&lt;/SPAN&gt;Portal sign in externally, using the external ip, public dns, or the Route 53 domain that I have pointing to the ALB, I get the redirect error above.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;This is from the browser console:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="background-color: #ffffff;"&gt;&lt;SPAN&gt;Invalid 'X-Frame-Options' header encountered when loading '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2F" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;mydomain.com&amp;gt;/arcgis/sharing/rest/oauth2/authorize?client_id=arcgisonline&amp;amp;redirect_uri=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2F" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;mydomain.com&amp;gt;/arcgis/home/postsignin.html&amp;amp;response_type=token&amp;amp;display=iframe&amp;amp;parent=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2F" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;mydomain.com&amp;gt;&amp;amp;expiration=20160&amp;amp;locale=en': 'ALLOW-FROM &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2F" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;mydomain.com&amp;gt;' is not a recognized directive. The header will be ignored.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;***I have not yet setup and configured ArcGIS Server to federate with this Portal***&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;Any ideas??&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 20:58:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511396#M19892</guid>
      <dc:creator>MikeSchonlau</dc:creator>
      <dc:date>2018-11-19T20:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511397#M19893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You'll need to go into your Portal admin page as the primary login and go to:&amp;nbsp;&lt;A class="link-titled" href="https://developers.arcgis.com/rest/enterprise-administration/portal/system-properties.htm" title="https://developers.arcgis.com/rest/enterprise-administration/portal/system-properties.htm"&gt;System Properties—ArcGIS REST API: Administer your portal | ArcGIS for Developers&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then,&amp;nbsp;update the PrivatePortalURL and WebContextURL to the Load Balancer DNS.&amp;nbsp; This will tell portal that the new DNS entry for the Load Balancer is the correct URL.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you'll want to do everything through these URLs going forward.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 21:35:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511397#M19893</guid>
      <dc:creator>JacobBoyle412</dc:creator>
      <dc:date>2018-11-19T21:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511398#M19894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This worked! You are a genius. I will email Jack D and tell him you deserve a raise, a promotion, and more vacation. Thanks!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 22:06:41 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511398#M19894</guid>
      <dc:creator>MikeSchonlau</dc:creator>
      <dc:date>2018-11-19T22:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511399#M19895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!&amp;nbsp; Feel free to PM me or post to this section of GeoNet if you have any further issues.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 22:24:24 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511399#M19895</guid>
      <dc:creator>JacobBoyle412</dc:creator>
      <dc:date>2018-11-19T22:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Use the Web adapter with AWS Certificate Manager?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511400#M19896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great - this is a really helpful post, Jacob. Took me a few tries, but I also have this configuration working well for me now.&lt;/P&gt;&lt;P&gt;Two additional questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is there any reason this wouldn’t be considered a valid production configuration?&lt;/LI&gt;&lt;LI&gt;Do both the PrivatePortalURL and the WebContextURL have to remain the constant&amp;nbsp;after federation? I’m wondering if there is a way to take an ami from one environment and, by changing the WebContextURL, use it in a second environment&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2019 20:30:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-the-web-adapter-with-aws-certificate-manager/m-p/511400#M19896</guid>
      <dc:creator>AndrewCullen</dc:creator>
      <dc:date>2019-03-19T20:30:34Z</dc:date>
    </item>
  </channel>
</rss>

