en-US
search-icon

Knowledge Base

How to enable SSL on Active Directory

Description

How to enable SSL on Active Directory

Resolution

Overview

To enable password changing the Active Directory used for authentication must be contacted using SSL


Resolution

Configuring Microsoft Active Directory for SSL access

Ensure that the Active Directory domain is set up. If the Certificate Authority (CA) is not installed, you can install it on your Active Directory server as follows:

  1. Click Start -> Control Panel -> Add or Remove Programs.

  2. Click Add/Remove Windows Components and select Certificate Services.

  3. Follow the procedure provided to install the Certificate Services CA.

Verifying that SSL is enabled on the Active Directory server

To verify that SSL has been enabled on the Active Directory server, do the following:

  1. Ensure that Windows Support Tools is installed on the Active Directory machine. The suptools.msi setup program is located in the SupportTools directory on your Windows installation CD.

  2. Select Start -> All Programs -> Windows Support Tools -> Command Prompt. Start the ldp tool by typing ldp at the command prompt.

  3. From the ldp window, select Connection -> Connect and supply the host name and port number (636). Also select the SSL check box.

    Note: Ensure that you type the Active Directory domain server name correctly.

If successful, a window is displayed listing information related to the Active Directory SSL connection. If the connection is unsuccessful, restart your system, and repeat this procedure.

Exporting the certificate from the Active Directory server

To export the CA certificate from the Active Directory server, follow these steps:

  1. Log on as a Domain Administrator to the Active Directory domain server that is being used.

  2. Export the certificate from the Active Directory server to a file. To do so, follow these steps:

    1. Click Start -> Control Panel -> Administrative Tools -> Certificate Authority to open the CA Microsoft Management Console (MMC) GUI.

    2. Highlight the CA machine and right-click to select its Properties.

    3. From General menu, click View Certificate.

    4. Select the Details view, and click the Copy to File button on the lower-right corner of the window.

    5. Use the Certificate Export Wizard to save the CA certificate in a file.

      Note: You can save the CA certificate in either DER Encoded Binary X-509 format or Based-64 Encoded X-509 format.

After you have extracted the public key certificate of the Certificate Authority (CA) of the Active Directory server, you must import this certificate to the Aventail SSL VPN using AMC (SSL Settings -> CA Certificates (Edit) -> New +).

Test the connection by opening the authentication server definition page in AMC and clicking Test connection. Also make sure you are indeed using SSL to connect to the AD.

SSL setup on the Active Directory Server is now complete.