2.9 KiB
tags
| tags | |||
|---|---|---|---|
|
Purpose
Export the CA chain or domain-controller certificate required by an application that connects to Active Directory over LDAPS. Use the certificate objects from the documented CA and domain-controller environment.
Export the LDAPS Certificate for Third-Party Applications
Some applications do not automatically trust your internal PKI and require you to manually install the certificate used by your domain controllers for LDAPS. In most cases, you should export the issuing CA certificates rather than the individual domain controller certificate. Only export the domain controller certificate if the third-party application explicitly requires it.
Export the Root and Subordinate CA Certificates
The Root CA and Subordinate CA certificates establish trust for every domain controller certificate issued by your PKI.
From any domain-joined system:
- Launch
certlm.msc- Navigate to "Trusted Root Certification Authorities > Certificates"
- Locate your Root CA certificate
- Right-click the certificate and select "All Tasks > Export..."
- Select "No, do not export the private key"
- Export the certificate as either:
DER encoded binary X.509 (.CER), orBase-64 encoded X.509 (.CER)
- Navigate to "Intermediate Certification Authorities > Certificates"
- Locate your Subordinate CA certificate
- Repeat the export process
- Navigate to "Trusted Root Certification Authorities > Certificates"
Import both certificates into the trusted certificate store required by the third-party application.
Export a Domain Controller Certificate
If the application requires the LDAPS server certificate itself:
- On the target domain controller, launch
certlm.msc- Navigate to "Personal > Certificates"
- Locate the certificate issued to the domain controller's FQDN that includes Server Authentication as an intended purpose
- If the certificate's intended purpose looks like
Client Authentication, Server Authentication, Smart Card Logon, KDC Authenticationthis cert may be more versatile for you.
- If the certificate's intended purpose looks like
- Right-click the certificate and select "All Tasks > Export..."
- Select "No, do not export the private key"
- Export the certificate as either:
DER encoded binary X.509 (.CER), orBase-64 encoded X.509 (.CER)
- Locate the certificate issued to the domain controller's FQDN that includes Server Authentication as an intended purpose
- Navigate to "Personal > Certificates"
!!! warning "Do Not Export the Private Key"
Third-party LDAPS clients require only the public certificate. Do not export the certificate as a .pfx file or include the private key unless the vendor explicitly documents that requirement.
Related Documentation
- Certificate Services Deployment — Identify the CA chain used by the LDAPS clients.
- Related Identity and Certificates Documentation — Find the connected deployments, procedures, and references for this subject.