跨两个信任Active Directory域配置LDAP over SSL的技术咨询
Hey there, let's work through this LDAPS setup for your two trusted domains without rocking the boat of your existing production environment. Since you don't have a CA already and want to avoid disruptions, here's a safe, step-by-step plan tailored to your scenario:
Skip the enterprise CA tied to your domains—go with a standalone root CA instead. This runs on a dedicated, non-domain-joined server (or even a temporary VM if you want to minimize footprint) so it won't integrate with your existing AD infrastructure, eliminating the risk of messing up domain services.
- Install the AD Certificate Services role on the dedicated server, choosing the "Standalone root CA" option during setup.
- Keep this CA offline when not issuing certificates to reduce attack surface (you can power it down after issuing the needed certs and only bring it back for renewals later).
LDAPS requires each domain controller (DC) in both example.local and example.com to have a valid server authentication certificate. Here's how to do this safely:
- On each DC, create a certificate request configuration file (let's call it
ldap-cert.inf) with content like this:[Version] Signature="$Windows NT$" [NewRequest] Subject = "CN=dc01.example.local" ; Replace with your DC's FQDN KeySpec = 1 KeyLength = 2048 Exportable = TRUE MachineKeySet = TRUE SMIME = FALSE PrivateKeyArchive = FALSE UserProtected = FALSE UseExistingKeySet = FALSE ProviderName = "Microsoft RSA SChannel Cryptographic Provider" ProviderType = 12 RequestType = PKCS10 [EnhancedKeyUsageExtension] OID=1.3.6.1.5.5.7.3.1 ; Server Authentication - Generate the request with this command:
certreq -new ldap-cert.inf dc-cert.req - Copy the
.reqfile to your standalone CA, then run this command to issue the certificate:certreq -accept dc-cert.req - Copy the issued
.cerfile back to the DC, then import it into the Local Computer > Personal > Certificates store viacertlm.msc.
Once the certificate is installed, you just need to refresh the LDAP service:
- Restart the Active Directory Domain Services (NTDS) service with these commands (do this during low-traffic hours to minimize impact):
net stop ntds net start ntds - Verify LDAPS is working using
ldp.exe:- Open
ldp.exe, go to Connection > Connect - Enter your DC's FQDN, port
636, check the SSL box - If the connection succeeds, you're good to go. You can also check the certificate details under Connection > View Certificate
- Open
Since your domains have a trust relationship, you can push the root CA's certificate to all machines in both domains via Group Policy, so your new software and domain computers will trust the LDAPS certificates:
- On your standalone CA, export the root certificate (without the private key, in Base64 format) using
certlm.msc(right-click the root cert > All Tasks > Export) - For each domain:
- Open Group Policy Management, edit the Default Domain Policy (or a dedicated policy if you prefer)
- Navigate to Computer Configuration > Windows Settings > Security Settings > Public Key Policies > Trusted Root Certification Authorities
- Right-click and select Import, then follow the wizard to import the root CA certificate
- Force a group policy update on all machines with:
gpupdate /force
- Configure your new software to connect to each DC on port
636(LDAPS) instead of the default 389. - If the software has its own trust store (common for third-party apps), import the root CA certificate there as well to ensure it trusts the DC's certificates.
- Run connection tests to confirm the software can bind to both domains securely over LDAPS.
Key Risk Mitigation Tips
- Keep the standalone CA offline: When you're not issuing/renewing certificates, power it down to avoid potential attacks.
- Test first in a staging environment: If you have a copy of your production setup, replicate the steps there before touching live DCs.
- Avoid modifying existing certs: We're only adding new server auth certs—your existing DC certificates (if any) won't be touched, so no disruption to current services.
内容的提问来源于stack exchange,提问作者Makorus

