From 098e924319124c3f402099646df9bcd83d027eff Mon Sep 17 00:00:00 2001 From: Nicole Rappe Date: Thu, 23 Jul 2026 14:33:14 -0600 Subject: [PATCH] Update deployments/services/authentication/Active Directory/Certificate Services.md --- .../authentication/Active Directory/Certificate Services.md | 1 + 1 file changed, 1 insertion(+) diff --git a/deployments/services/authentication/Active Directory/Certificate Services.md b/deployments/services/authentication/Active Directory/Certificate Services.md index 6cdab08..612f4ac 100644 --- a/deployments/services/authentication/Active Directory/Certificate Services.md +++ b/deployments/services/authentication/Active Directory/Certificate Services.md @@ -642,6 +642,7 @@ If the application requires the LDAPS server certificate itself: * On the target domain controller, launch `certlm.msc` * Navigate to "**Personal > Certificates**" * Locate the certificate issued to the domain controller's FQDN that includes **Server Authentication** as an intended purpose + * If the certificate's intended purpose looks like `Client Authentication, Server Authentication, Smart Card Logon, KDC Authentication` this cert may be more versatile for you. * Right-click the certificate and select "**All Tasks > Export...**" * Select "**No, do not export the private key**" * Export the certificate as either: