Files
docs/workflows/Identity and Certificates/Certificates/Export Certificates for LDAPS Clients.md
T
nicole 289769a601
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
Restructured Documentation
2026-09-05 14:08:43 -06:00

2.9 KiB

tags
tags
Active Directory
LDAPS
Certificates

Purpose

Export the CA chain or domain-controller certificate required by an application that connects to Active Directory over LDAPS. Use the certificate objects from the documented CA and domain-controller environment.

Export the LDAPS Certificate for Third-Party Applications

Some applications do not automatically trust your internal PKI and require you to manually install the certificate used by your domain controllers for LDAPS. In most cases, you should export the issuing CA certificates rather than the individual domain controller certificate. Only export the domain controller certificate if the third-party application explicitly requires it.

Export the Root and Subordinate CA Certificates

The Root CA and Subordinate CA certificates establish trust for every domain controller certificate issued by your PKI.

From any domain-joined system:

  • Launch certlm.msc
    • Navigate to "Trusted Root Certification Authorities > Certificates"
      • Locate your Root CA certificate
      • Right-click the certificate and select "All Tasks > Export..."
        • Select "No, do not export the private key"
        • Export the certificate as either:
          • DER encoded binary X.509 (.CER), or
          • Base-64 encoded X.509 (.CER)
    • Navigate to "Intermediate Certification Authorities > Certificates"
      • Locate your Subordinate CA certificate
      • Repeat the export process

Import both certificates into the trusted certificate store required by the third-party application.

Export a Domain Controller Certificate

If the application requires the LDAPS server certificate itself:

  • On the target domain controller, launch certlm.msc
    • Navigate to "Personal > Certificates"
      • Locate the certificate issued to the domain controller's FQDN that includes Server Authentication as an intended purpose
        • If the certificate's intended purpose looks like Client Authentication, Server Authentication, Smart Card Logon, KDC Authentication this cert may be more versatile for you.
      • Right-click the certificate and select "All Tasks > Export..."
        • Select "No, do not export the private key"
        • Export the certificate as either:
          • DER encoded binary X.509 (.CER), or
          • Base-64 encoded X.509 (.CER)

!!! warning "Do Not Export the Private Key" Third-party LDAPS clients require only the public certificate. Do not export the certificate as a .pfx file or include the private key unless the vendor explicitly documents that requirement.