Note Only LDAP data transfers are exposed. Other authentication or authorization data using Kerberos, SASL, and even NTLM have their own encryption systems. The Microsoft Management Console (mmc) snap-ins, since Windows 2000 SP4 have used LDAP sign and seal or Simple Authentication and Security Layer (SASL) and replication between domain controllers is encrypted using Kerberos.
Warning Before you install a certification authority (CA), you should be aware that you are creating or extending a public key infrastructure (PKI). Be sure to design a PKI that is appropriate for your organization. See PKI Design Brief Overview for additional information.
To request a certificate from your LDAPSL server, do the following on each domain controller that requires LDAPS connections:
Kurt L Hudson MSFT edited Revision 50. Comment: Updated to show that it still applies to Windows Server 2012
Richard Mueller edited Revision 48. Comment: Fixed HTML for TOC, all header lines blue
Richard Mueller edited Revision 47. Comment: Fixed <a name> tags to make TOC work, add tag
Kurt L Hudson edited Revision 43. Comment: Added link to troubleshooting PKI
Kurt L Hudson edited Revision 42. Comment: Added a link to how to add subject alternative name to secure LDAP certificate article as this comes up routinely
Kurt L Hudson edited Revision 40. Comment: Adding certificate to the article title because that is a popular keyword search from customers
Kurt L Hudson edited Revision 39. Comment: Fixed an odd bold formatting issue between two links
Kurt L Hudson edited Revision 38. Comment: Modified formatting to be more consistent
Kurt L Hudson edited Revision 37. Comment: Revised the troubleshooting section based on customer feedback
Kurt L Hudson edited Revision 36. Comment: Updated formatting
support.microsoft.com/.../938703 for troubleshooting.
nice