--- tags: - Active Directory - LDAPS - Certificates --- ## Purpose Export the CA chain or domain-controller certificate required by an application that connects to Active Directory over LDAPS. Use the certificate objects from the documented CA and domain-controller environment. ## Export the LDAPS Certificate for Third-Party Applications Some applications do not automatically trust your internal PKI and require you to manually install the certificate used by your domain controllers for LDAPS. In most cases, you should export the issuing CA certificates rather than the individual domain controller certificate. Only export the domain controller certificate if the third-party application explicitly requires it. ### Export the Root and Subordinate CA Certificates The Root CA and Subordinate CA certificates establish trust for every domain controller certificate issued by your PKI. From any domain-joined system: - Launch `certlm.msc` - Navigate to "**Trusted Root Certification Authorities > Certificates**" - Locate your Root CA certificate - Right-click the certificate and select "**All Tasks > Export...**" - Select "**No, do not export the private key**" - Export the certificate as either: - `DER encoded binary X.509 (.CER)`, or - `Base-64 encoded X.509 (.CER)` - Navigate to "**Intermediate Certification Authorities > Certificates**" - Locate your Subordinate CA certificate - Repeat the export process Import both certificates into the trusted certificate store required by the third-party application. ### Export a Domain Controller Certificate If the application requires the LDAPS server certificate itself: - On the target domain controller, launch `certlm.msc` - Navigate to "**Personal > Certificates**" - Locate the certificate issued to the domain controller's FQDN that includes **Server Authentication** as an intended purpose - If the certificate's intended purpose looks like `Client Authentication, Server Authentication, Smart Card Logon, KDC Authentication` this cert may be more versatile for you. - Right-click the certificate and select "**All Tasks > Export...**" - Select "**No, do not export the private key**" - Export the certificate as either: - `DER encoded binary X.509 (.CER)`, or - `Base-64 encoded X.509 (.CER)` !!! warning "Do Not Export the Private Key" Third-party LDAPS clients require only the public certificate. Do **not** export the certificate as a `.pfx` file or include the private key unless the vendor explicitly documents that requirement. ## Related Documentation - [Certificate Services Deployment](<../../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Identify the CA chain used by the LDAPS clients. - [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.