--- tags: - Identity and Certificates - Reference - Documentation --- # Identity and Certificates ## Purpose Connect directory services, certificate trust, single sign-on, and application authentication. Start with the identity system involved, then follow the integration or maintenance procedure. ## Includes - Build the documented offline root, online subordinate CA, and publication point. - Publish and monitor CRLs after the PKI exists. - Provide the trust material needed by directory clients. ## Find the Right Document - [Deploy Certificate Services](<../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Build the documented offline root, online subordinate CA, and publication point. - [Maintain Revocation Lists](<../../workflows/Identity and Certificates/Certificates/Publish and Maintain Certificate Revocation Lists.md>) — Publish and monitor CRLs after the PKI exists. - [Export LDAPS Certificates](<../../workflows/Identity and Certificates/Certificates/Export Certificates for LDAPS Clients.md>) — Provide the trust material needed by directory clients. - [LDAP Connection Settings]() — Locate the recorded directory connection parameters. - [Keycloak Application Integrations]() — Choose reverse-proxy authentication or an application-specific OAuth integration. - [Windows Remote Management](<../../workflows/Identity and Certificates/Windows/Enable WinRM over HTTPS.md>) — Prepare Windows targets for the AWX or Puppet Bolt workflows that reference WinRM.