Step by step guide to setup LDAPS on Windows Server using Certificate Authority
- First, we need to set up LDAP over SSL (LDAPS) to establish a secure connection between our client and the LDAP server.
- To do this, we install the "Active Directory Certificate Services" role on our Windows Server Machine. You can do this by following these steps:
- Click on the Start menu.
- Open Server Manager.
- Click on "Add Roles and Features".
- From there, follow the instructions to install the role. This will allow us to create and export the necessary certificate for our LDAPS connection.
- After selecting Add Roles and Features and Click on Next.
- Choose Role-based or feature-based installation option and Click on Next button.
data:image/s3,"s3://crabby-images/d0451/d04513a354fa47697b29ca0789542c6dbfed9660" alt=""
- Choose Select a server from the server pool option & Select ldap server from the server pool and click on Next button.
data:image/s3,"s3://crabby-images/659dc/659dc4a57b497326c188b9557a15a5044aceecde" alt=""
- Choose Active Directory Certificate Services option from the list of roles and click on Next button.
data:image/s3,"s3://crabby-images/307ea/307ea97b0bef5bc1152cfe8ebde72f3e4321576a" alt=""
- Choose nothing from the list of features and click on Next button.
Click on Add Features
data:image/s3,"s3://crabby-images/b31b7/b31b701c1f2b087c4142838024f6f5dbe8a6912a" alt=""
data:image/s3,"s3://crabby-images/88ae6/88ae6caa185d6b4c6221cfd13f8d789272b29f54" alt="A screenshot of a computer
Description automatically generated"
data:image/s3,"s3://crabby-images/b4652/b4652a9d1c3285222b19f9ce4b6622f16c3e37ae" alt=""
data:image/s3,"s3://crabby-images/cb5cf/cb5cf32446aef99584a0f84f2cf13915ad053fcf" alt="A screenshot of a computer
Description automatically generated"
Make sure Active Directory Certificate Services and Certificate Authority Web Enrollment both are selected
data:image/s3,"s3://crabby-images/85d1e/85d1e37e7c1f7646a5759ea3547ceb32839ca7bb" alt=""
On the Confirmation page, select Restart the destination server automatically if required and press Install.
data:image/s3,"s3://crabby-images/3ba07/3ba07093418789ea6018dbe6b366d50740d7102c" alt=""
After installation, go to the notification tab and click Configure Active Directory Certificate Services.
data:image/s3,"s3://crabby-images/1a5ce/1a5ce0716a323913702cb832f221a091c9b9f7e8" alt=""
On the Credentials page, input the Credentials and click Next.
data:image/s3,"s3://crabby-images/a1a7e/a1a7e97daf24032fa60b4a075114efff0fe0b03d" alt=""
On the Role Services page, select Certification Authority Web Enrollment and Click Next.
data:image/s3,"s3://crabby-images/8e6c6/8e6c655c46ab6cc482e6b21733b928068d418988" alt=""
Specify the setup type of the CA
data:image/s3,"s3://crabby-images/5399f/5399f89cb68ad8c34e6482460318865e1ae21e7a" alt="A screenshot of a computer
Description automatically generated"
data:image/s3,"s3://crabby-images/4ade9/4ade914102c47e39bf9f6eff4687005c3e953996" alt=""
If you already have the old private key please use the 2nd option.
data:image/s3,"s3://crabby-images/d4d88/d4d88d18a7338a0cd3bc3fa68e4ad5e83d298abf" alt=""
data:image/s3,"s3://crabby-images/1df37/1df371501ce7b80e75a503abfabaf575e0e9e2b8" alt="A screenshot of a computer
Description automatically generated"
On the Confirmation page, click Configure to finish configuration.
data:image/s3,"s3://crabby-images/7a100/7a100c112c1ae34372aa97ce14a083b928443fc4" alt=""
data:image/s3,"s3://crabby-images/5934a/5934a1e51e55ce88345da75d1d229e5c1e4f887e" alt=""
1.2: Create certificate template
- Go to Windows Key+R and run certtmpl.msc command and choose the Kerberos Authentication Template.
data:image/s3,"s3://crabby-images/f9333/f93335944dfbb829d88e5651898f6181aa28c704" alt="LDAPS on Windows Server certificate authority"
Right-click on Kerberos Authentication and then select Duplicate Template.
data:image/s3,"s3://crabby-images/60ae3/60ae35a1adae111154311e004fbe7673c1128b7f" alt="LDAPS on Windows Server duplicate kerberos authenticator template"
- The Properties of New Template will appear. Configure the setting according to your requirements.
- Go to the General tab and Enable publish certificate in Active Directory option.
data:image/s3,"s3://crabby-images/0a37f/0a37fa64f6ee5bae569fc4b49ed169e08b19ee34" alt=""
- Go to the Request Handling Tab and Enable ‘Allow private key to be exported’ option.
data:image/s3,"s3://crabby-images/639cf/639cf5ab9a3c66842eb8333c25e2b15466c71e39" alt="LDAPS on Windows Server ldap certificate install"
- Go to the Subject Name tab and Enable subject name format as DNS Name and click on Apply & OK button.
data:image/s3,"s3://crabby-images/fdfb1/fdfb1b4baec6f5fc8476692ea034385735b7f744" alt="LDAPS on Windows Server subject name settings"
1.3: Issue certificate template
- Go to Start -> Certification Authority Right click on "Certificate Templates" and select New-> Certificate Template to Issue.
data:image/s3,"s3://crabby-images/dab1c/dab1c85b1f07e402e71f6e3e4d018acb449f80f8" alt="LDAPS on Windows Server certificate authority"
- Now, select your recently created Certificate Template and click on ok button.
data:image/s3,"s3://crabby-images/db5bc/db5bccdca268111f34c59c40ee7fd1d89b9bd7ec" alt=""
1.4: Request new certificate for created certificate template
- Go to Windows Key+R -> mmc -> File -> Add/Remove snap-in. Select Certificates, and click on Add button and then click on Ok button .
data:image/s3,"s3://crabby-images/ab1df/ab1df0a7c03c46206ae66e842731969d7026bd5f" alt="LDAPS on Windows Server certificate authority"
- Select Computer account option and click on Next button.
data:image/s3,"s3://crabby-images/a3dc4/a3dc4c09a4060d53142a909fe5365d8274e7b85c" alt="LDAPS on Windows Server select computer account"
- Select Local computer option and click on Finish button.
data:image/s3,"s3://crabby-images/86125/86125094691cc64692cf431036f4640083a05cb7" alt="LDAPS on Windows Server select local computer"
- Now, right Click on Certificates select All Tasks and click on Request for new Certificate.
data:image/s3,"s3://crabby-images/26b0a/26b0ae28453be7b2a681e0ca8d56a43a6ad59a80" alt=""
- Click on Next button.
- Click on Next button.
- Select your certificate and click on Enroll button.
- Click on Finish button.
1.5: Export the created certificate
- Right click on recently generated certificate and select All tasks -> Export.
- Click on Next button.
data:image/s3,"s3://crabby-images/77fc7/77fc743a00292616cf730b4346d3721ed57d21eb" alt="LDAPS on Windows Server duplicate kerberos authenticator"
- Select Do not export the private key option and click on Next button.
- Choose Base-64 encoded X .509 file format and click on Next.
data:image/s3,"s3://crabby-images/65f82/65f823ed91977b3125ed7b7d437feea2cf5d068f" alt="LDAPS on Windows Server base-64 encoded"
- Export the .CER to your local system path and click on Next.
- Click on Finish button to complete the certificate export.
data:image/s3,"s3://crabby-images/0fc80/0fc80ce00c0f7d9af80a55a3a818a0e0db5566af" alt="LDAPS on Windows Server export certificate successfully"
2. Configure LDAPS on the Connector
- First, we need to change the certificate format from .cer to .pem.
- Then, upload the certificate to the Anyware Manager.
- Finally, copy the configuration command and run it on the connector.