<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Federation - Administration URL: machine name/FQDN vs DNS - inconsistent behavior across installations in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/federation-administration-url-machine-name-fqdn-vs/m-p/1719053#M44496</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/572383"&gt;@denniszammarchi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I always recommend federating with the same URL you use for your Services URL.&amp;nbsp; This is a requirement when you have a multi-machine ArcGIS Server site.&amp;nbsp; You want Portal to be able to communicate to the ArcGIS Server instance if one of the servers is down.&amp;nbsp; I realize you may not have a multi-machine site, but if you do join another machine to your ArcGIS Server site, you won't have to worry about updating the federation URL.&lt;/P&gt;&lt;P&gt;As for why it's failing, are you importing any certificates into ArcGIS Server's internal tomcat web server, and configuring ArcGIS Server to use this (steps in link below)?&lt;/P&gt;&lt;P&gt;&lt;A href="https://doc.esri.com/en/arcgis-enterprise/latest/administer/configuring-https-using-an-existing-ssl-certificate.html?pivots=os-windows#B00" target="_blank"&gt;https://doc.esri.com/en/arcgis-enterprise/latest/administer/configuring-https-using-an-existing-ssl-certificate.html?pivots=os-windows#B00&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Aug 2026 18:20:14 GMT</pubDate>
    <dc:creator>JakeSkinner</dc:creator>
    <dc:date>2026-08-06T18:20:14Z</dc:date>
    <item>
      <title>Federation - Administration URL: machine name/FQDN vs DNS - inconsistent behavior across installations</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/federation-administration-url-machine-name-fqdn-vs/m-p/1718899#M44493</link>
      <description>&lt;P class=""&gt;Hi everyone,&lt;/P&gt;&lt;P class=""&gt;We've run into inconsistent behavior when federating ArcGIS Server with Portal for ArcGIS, and I'd like to get some input from the community.&lt;/P&gt;&lt;P class=""&gt;Our standard approach:&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;STRONG&gt;Services URL&lt;/STRONG&gt;: we use the URL configured through the Web Adaptor, matching the DNS name registered for the environment.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Administration URL&lt;/STRONG&gt;: as a first choice, we try to use the machine name (or FQDN, when available) on port 6443&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="denniszammarchi_1-1786006226697.png" style="width: 291px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/156369i24AC0D65172CB61D/image-dimensions/291x150?v=v2" width="291" height="150" role="button" title="denniszammarchi_1-1786006226697.png" alt="denniszammarchi_1-1786006226697.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The issue:&lt;/STRONG&gt;&lt;BR /&gt;In some installations, using the machine name (or FQDN) for the Administration URL doesn't work correctly, and we're forced to fall back to using the same DNS name we use for the Services URL (just on port 6443) instead. Interestingly, this happens even on single-machine deployments, where we wouldn't necessarily expect name resolution or certificate issues to come into play. We've seen this behavior recur across multiple versions (11.0 through 12.1), not tied to one specific release.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Is there a recommended best practice for choosing between machine name/FQDN and DNS name for the Administration URL during federation?&lt;/P&gt;&lt;P&gt;What typically causes the machine name/FQDN approach to fail — could this be related to wildcard certificate SAN/CN matching, internal DNS resolution, or hosts file configuration? We use wildcard SSL certificates in PFX format across all our installations&lt;/P&gt;&lt;P&gt;Any insights, best practices, or documentation pointers would be greatly appreciated. Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 08:52:37 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/federation-administration-url-machine-name-fqdn-vs/m-p/1718899#M44493</guid>
      <dc:creator>denniszammarchi</dc:creator>
      <dc:date>2026-08-06T08:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Federation - Administration URL: machine name/FQDN vs DNS - inconsistent behavior across installations</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/federation-administration-url-machine-name-fqdn-vs/m-p/1719053#M44496</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/572383"&gt;@denniszammarchi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I always recommend federating with the same URL you use for your Services URL.&amp;nbsp; This is a requirement when you have a multi-machine ArcGIS Server site.&amp;nbsp; You want Portal to be able to communicate to the ArcGIS Server instance if one of the servers is down.&amp;nbsp; I realize you may not have a multi-machine site, but if you do join another machine to your ArcGIS Server site, you won't have to worry about updating the federation URL.&lt;/P&gt;&lt;P&gt;As for why it's failing, are you importing any certificates into ArcGIS Server's internal tomcat web server, and configuring ArcGIS Server to use this (steps in link below)?&lt;/P&gt;&lt;P&gt;&lt;A href="https://doc.esri.com/en/arcgis-enterprise/latest/administer/configuring-https-using-an-existing-ssl-certificate.html?pivots=os-windows#B00" target="_blank"&gt;https://doc.esri.com/en/arcgis-enterprise/latest/administer/configuring-https-using-an-existing-ssl-certificate.html?pivots=os-windows#B00&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 18:20:14 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/federation-administration-url-machine-name-fqdn-vs/m-p/1719053#M44496</guid>
      <dc:creator>JakeSkinner</dc:creator>
      <dc:date>2026-08-06T18:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Federation - Administration URL: machine name/FQDN vs DNS - inconsistent behavior across installations</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/federation-administration-url-machine-name-fqdn-vs/m-p/1719369#M44506</link>
      <description>&lt;P class=""&gt;Hello&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/572383"&gt;@denniszammarchi&lt;/a&gt;,&amp;nbsp;&lt;BR /&gt;To confirm this is a certificate issue, temporarily revert both to self-signed:&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;Revert ArcGIS Server to its default self-signed certificate (&lt;A href="https://machine:6443/arcgis/admin/machines/" target="_blank" rel="noopener"&gt;https://machine:6443/arcgis/admin/machines/&lt;/A&gt;&amp;lt;machinename&amp;gt;/sslcertificates)&lt;/LI&gt;&lt;LI&gt;Revert Portal to its default self-signed certificate (&lt;A href="https://machine:7443/arcgis/portaladmin/security/sslCertificates" target="_blank" rel="noopener"&gt;https://machine:7443/arcgis/portaladmin/security/sslCertificates&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;These steps will restart the services of Portal and Server&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Attempt federation using the machine name&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;If federation works -&amp;gt; then this might be a wildcard certificate naming issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2026 21:12:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/federation-administration-url-machine-name-fqdn-vs/m-p/1719369#M44506</guid>
      <dc:creator>OlaIHamed</dc:creator>
      <dc:date>2026-08-07T21:12:38Z</dc:date>
    </item>
  </channel>
</rss>

