Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (2024)

Account Management » Active Directory How-To pages

How to install SSL certificates in Active Directory?

Active Directory read and write requests made across the network can be made secure using SSL. It requires a CA (Certificate Authority) certificate. This article explains the steps to be followed while configuring SSL certificate in Active Directory.

Prerequisites to install SSL certificates:

  • Internet Information Services - IIS is required before you install
    Windows Certificate services.
  • Windows Certificate services.

Steps to install SSL certificate:

Step 1: Install Active Directory Certificate Services

  • Log into your Active Directory Server as an administrator.
  • Open Server Manager → Roles Summary→ Add roles.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (1)

  • In the Add Roles Wizard, select Server Roles. From the options listed, select Active Directory Certificate Services, and click next. In the next screen, click Next again to proceed.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (2)

  • On the next page, select Certification Authority role service to issue and manage certificates.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (3)

  • In the Specify Setup Type page, select Enterprise as your server is a part of the AD environment. Click Next.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (4)

  • Next is the "Specify CA Type" page. If this is your first CA, select Root CA. Else, select Subordinate CA.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (5)

  • Set the private key to be used for this CA.Since this is a new CA, select "Create a new private key" and click Next. In the next screen, click Next again to proceed.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (6)

  • On the next page, choose a common name and a distinguished name suffix for your CA. Check the preview of your CA's complete distinguished name, then click Next if you are satisfied with your selections.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (7)

  • In the "Set validity page", accept the default value or set a validity period of your own. The CA will issue certificates that are valid only till this period.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (8)

  • Select a location for storing the Certificate database and the Certificate database logs.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (9)

  • Confirm your installation configurations and click Install. Once the installation is completed successfully, close the wizard.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (10)

Step 2: Obtain the server certificate

After installing the Certification Authority, you now need to add the SSL certificates that are used by your application servers to the list of accepted certificates.

The Active Directory certificate is automatically generated and stored in the root of the C drive. To export the certificate, execute this command on the server:
certutil -ca.cert client.crt

Step 3: Import the server certificate

The certificate has to be imported into your Java Runtime Environment for an application server to trust your AD certificate. The JDK stores trusted certificates in a file called a keystore. The default keystore file is called cacerts and it is stored in the jre\lib\security sub-directory of your Java installation. Run the following commands on your server to import the certificates.

  • Navigate to the directory in which Java is installed.
    cd /d C:\Program Files\Java\jdk1.5.0_12
  • Run the command mentioned below, where server-certificate.crt is the name of the file from your directory server.
    keytool -importcert -keystore .\jre\lib\security\cacerts -file server-certificate.crt
  • Enter the default keystore password changeit when prompted.
  • When prompted Trust this certificate? [no]: enter yes to confirm the key import:

    Enter keystore password: changeit
    Owner: CN=ad01, C=US
    Issuer: CN=ad01, C=US
    Serial number: 15563d6677a4e9e4582d8a84be683f9
    Valid from: Tue Aug 21 01:10:46 ACT 2007 until: Tue Aug 21 01:13:59 ACT 2012
    Certificate fingerprints:
    MD5:D6:56:F0:23:16:E3:62:2C:6F:8A:0A:37:30:A1:84:BE
    SHA1:73:73:4E:A6:A0:D1:4E:F4:F3:CD:CE:BE:96:80:35:D2:B4:7C:79:C1
    Trust this certificate? [no]: yes
    Certificate was added to keystore

  • Change 'URL' to use LDAP over SSL and use the 'Secure SSL' option when connecting your application to your directory server.

Once the certificate has been imported as per the above instructions, you will need to restart the application to apply the changes made.

Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (2024)
Top Articles
Top 5 Risk Mitigation Strategies for Business Success
Foodies left ‘devastated’ that Ronzoni will discontinue its beloved star-shaped pastina | CNN Business
Omega Pizza-Roast Beef -Seafood Middleton Menu
Artem The Gambler
123 Movies Black Adam
O'reilly's Auto Parts Closest To My Location
855-392-7812
Readyset Ochsner.org
Google Jobs Denver
Wausau Marketplace
Ub Civil Engineering Flowsheet
THE 10 BEST River Retreats for 2024/2025
Becky Hudson Free
12 Best Craigslist Apps for Android and iOS (2024)
Price Of Gas At Sam's
Enterprise Car Sales Jacksonville Used Cars
Farmer's Almanac 2 Month Free Forecast
2020 Military Pay Charts – Officer & Enlisted Pay Scales (3.1% Raise)
Persona 5 Royal Fusion Calculator (Fusion list with guide)
Air Quality Index Endicott Ny
Engineering Beauties Chapter 1
Cb2 South Coast Plaza
Craigslist Rome Ny
Xxn Abbreviation List 2017 Pdf
Jurassic World Exhibition Discount Code
Xxn Abbreviation List 2023
J&R Cycle Villa Park
60 Second Burger Run Unblocked
Sf Bay Area Craigslist Com
Craigslist Gigs Norfolk
Six Flags Employee Pay Stubs
How to Get Into UCLA: Admissions Stats + Tips
Ark Unlock All Skins Command
Cruise Ships Archives
AsROck Q1900B ITX und Ramverträglichkeit
Build-A-Team: Putting together the best Cathedral basketball team
Greater Keene Men's Softball
Winco Money Order Hours
968 woorden beginnen met kruis
How Does The Common App Work? A Guide To The Common App
Patricia And Aaron Toro
844 386 9815
Ts In Baton Rouge
Sapphire Pine Grove
UNC Charlotte Admission Requirements
Muni Metro Schedule
Latina Webcam Lesbian
Razor Edge Gotti Pitbull Price
Aaca Not Mine
Latest Posts
Article information

Author: Rubie Ullrich

Last Updated:

Views: 6152

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.