Note Only LDAP data transfers are exposed. Other authentication or authorization data using Kerberos, SASL, and even NTLM have their own encryption systems. The Microsoft Management Console (mmc) snap-ins, since Windows 2000 SP4 have used LDAP sign and seal or Simple Authentication and Security Layer (SASL) and replication between domain controllers is encrypted using Kerberos.
Warning Before you install a certification authority (CA), you should be aware that you are creating or extending a public key infrastructure (PKI). Be sure to design a PKI that is appropriate for your organization. See PKI Design Brief Overview for additional information.
To request a certificate from your LDAPSL server, do the following on each domain controller that requires LDAPS connections:
Kurt L Hudson MSFT edited Revision 50. Comment: Updated to show that it still applies to Windows Server 2012
Kurt L Hudson edited Original. Comment: updated the error message
Kurt L Hudson edited Revision 1. Comment: Completed the basic version of this article. Plan to enter more step-by-step instructions in the future or create and point out to them.
Kurt L Hudson edited Revision 2. Comment: Fixed a typo
Kurt L Hudson edited Revision 3. Comment: Updated a bit to clarify the items about LDAP signing
Kurt L Hudson edited Revision 4. Comment: Updated based of feedback from Florent Reynal de Saint Michel
Kurt L Hudson edited Revision 5. Comment: Updated content to include steps about getting a server authentication certificate
Kurt L Hudson edited Revision 6. Comment: Added figures
Kurt L Hudson edited Revision 7. Comment: updated formatting
Kurt L Hudson edited Revision 8. Comment: Updated formatting to make the request part an H4 and created min-TOC
support.microsoft.com/.../938703 for troubleshooting.
Kurt L Hudson edited Revision 1. Comment: Completed the basic version of this article. Plan to enter more step-by-step instructions in the future o