diff --git a/deployments/services/authentication/Active Directory/Certificate Services.md b/deployments/services/authentication/Active Directory/Certificate Services.md index 6cdab08..612f4ac 100644 --- a/deployments/services/authentication/Active Directory/Certificate Services.md +++ b/deployments/services/authentication/Active Directory/Certificate Services.md @@ -642,6 +642,7 @@ If the application requires the LDAPS server certificate itself: * On the target domain controller, launch `certlm.msc` * Navigate to "**Personal > Certificates**" * Locate the certificate issued to the domain controller's FQDN that includes **Server Authentication** as an intended purpose + * If the certificate's intended purpose looks like `Client Authentication, Server Authentication, Smart Card Logon, KDC Authentication` this cert may be more versatile for you. * Right-click the certificate and select "**All Tasks > Export...**" * Select "**No, do not export the private key**" * Export the certificate as either: