Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (2024)

Account Management » Active Directory How-To pages

How to install SSL certificates in Active Directory?

Active Directory read and write requests made across the network can be made secure using SSL. It requires a CA (Certificate Authority) certificate. This article explains the steps to be followed while configuring SSL certificate in Active Directory.

Prerequisites to install SSL certificates:

  • Internet Information Services - IIS is required before you install
    Windows Certificate services.
  • Windows Certificate services.

Steps to install SSL certificate:

Step 1: Install Active Directory Certificate Services

  • Log into your Active Directory Server as an administrator.
  • Open Server Manager → Roles Summary→ Add roles.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (1)

  • In the Add Roles Wizard, select Server Roles. From the options listed, select Active Directory Certificate Services, and click next. In the next screen, click Next again to proceed.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (2)

  • On the next page, select Certification Authority role service to issue and manage certificates.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (3)

  • In the Specify Setup Type page, select Enterprise as your server is a part of the AD environment. Click Next.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (4)

  • Next is the "Specify CA Type" page. If this is your first CA, select Root CA. Else, select Subordinate CA.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (5)

  • Set the private key to be used for this CA.Since this is a new CA, select "Create a new private key" and click Next. In the next screen, click Next again to proceed.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (6)

  • On the next page, choose a common name and a distinguished name suffix for your CA. Check the preview of your CA's complete distinguished name, then click Next if you are satisfied with your selections.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (7)

  • In the "Set validity page", accept the default value or set a validity period of your own. The CA will issue certificates that are valid only till this period.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (8)

  • Select a location for storing the Certificate database and the Certificate database logs.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (9)

  • Confirm your installation configurations and click Install. Once the installation is completed successfully, close the wizard.

    Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (10)

Step 2: Obtain the server certificate

After installing the Certification Authority, you now need to add the SSL certificates that are used by your application servers to the list of accepted certificates.

The Active Directory certificate is automatically generated and stored in the root of the C drive. To export the certificate, execute this command on the server:
certutil -ca.cert client.crt

Step 3: Import the server certificate

The certificate has to be imported into your Java Runtime Environment for an application server to trust your AD certificate. The JDK stores trusted certificates in a file called a keystore. The default keystore file is called cacerts and it is stored in the jre\lib\security sub-directory of your Java installation. Run the following commands on your server to import the certificates.

  • Navigate to the directory in which Java is installed.
    cd /d C:\Program Files\Java\jdk1.5.0_12
  • Run the command mentioned below, where server-certificate.crt is the name of the file from your directory server.
    keytool -importcert -keystore .\jre\lib\security\cacerts -file server-certificate.crt
  • Enter the default keystore password changeit when prompted.
  • When prompted Trust this certificate? [no]: enter yes to confirm the key import:

    Enter keystore password: changeit
    Owner: CN=ad01, C=US
    Issuer: CN=ad01, C=US
    Serial number: 15563d6677a4e9e4582d8a84be683f9
    Valid from: Tue Aug 21 01:10:46 ACT 2007 until: Tue Aug 21 01:13:59 ACT 2012
    Certificate fingerprints:
    MD5:D6:56:F0:23:16:E3:62:2C:6F:8A:0A:37:30:A1:84:BE
    SHA1:73:73:4E:A6:A0:D1:4E:F4:F3:CD:CE:BE:96:80:35:D2:B4:7C:79:C1
    Trust this certificate? [no]: yes
    Certificate was added to keystore

  • Change 'URL' to use LDAP over SSL and use the 'Secure SSL' option when connecting your application to your directory server.

Once the certificate has been imported as per the above instructions, you will need to restart the application to apply the changes made.

Real-time, web based Active Directory Change Auditing and Reporting Solution by ManageEngine ADAudit Plus (2024)
Top Articles
FOX13 Investigates: Why some foods sold legally in the U.S. are banned overseas
FAQs | Allianz Travel Insurance
Moto X3M Game - Play Unblocked Game Online for Free!
Oriellys Bad Axe
Advanced Eye Care Bowling Green Missouri
Jewel-Osco Pharmacy Locations
Trauma Care | FMOLHS
I Have Possessed The Body Of The Protagonist Spoilers
Www.metaquest/Device Code
Patriot Ledger Obits Today
Gopher Hockey Forum
Massagefinder Female
Bayview Freeborn Funeral Home | Albert Lea, Minnesota
What is a TN-C-S Earthing System? Definition, Meaning, Diagrams
702-550-8761
From Point and Click to Qmlativ: Illinois District Evolves Alongside EdTech Provider
Walmart Supercenter Nearest To My Location
Caro Walmart Hair Salon
Prettyaline
Memphis Cars For Sale Craigslist
Theresa Alone Gofundme
The Creator Showtimes Near Regal La Live
German American Bank Owenton Ky
Craigslist Ocala Garage Sales
R/Altfeet
Funny Marco Birth Chart
Magicseaweed Vero Beach
LA ABUELA (2021) – „Sie wartet auf Dich“ | Filmkritik
Bolivar Street Boutique
Monster Hunter Rise Steam Unlocked
10-Day Weather Forecast for Denver, CO - The Weather Channel | weather.com
Library History Round Table
Emerson Naturals Kratom
Moxxie/Relationships
Craigslist Bronx Ny Free Stuff
Sra Memorialcare
Uncovering The Mystery Behind Crazyjamjam Fanfix Leaked
Eaton Chevrolet Gmc Houston Photos
Texas Gov Ecommdirect Con
Angie Lynn Blankenship
Power Outage Map Albany Ny
South Florida residents must earn more than $100,000 to avoid being 'rent burdened'
Full Cast Of Red
Cost Cutters In Calallen
Craigslist Placer County
Tamusso
Cookie Clicker The Advanced Method
Lowest Price Traffic School Answers
65 snow quotes guaranteed to warm your heart this winter
Denys Davydov - Wikitia
Latest Posts
Article information

Author: Rubie Ullrich

Last Updated:

Views: 6152

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.