Changing SSL certificate for Secure LDAP in Entra Domain services fails

Paul Gaffney 20 Reputation points
2024-04-18T17:42:28.9166667+00:00

Having an issue changing the SSL certificate for Secure LDAP domain service in Entra.

Existing certificate will expire in 30 days.

What I have tried:

  • Submitted new certificate request with an external certificate authority. (same as current certificate authority)
  • Certificate request was for a wildcard SSL certificate in the form of *.domain.name
  • Received certificate. Imported into my computer. Exported via certificate manager in 3DES as a PFX file containing private key - password protected.
  • On Entra domain services console, secure ldap - "change certificate". pointed to new PFX file and supplied password for PFX file.
  • Fails installation.
  • Compared existing certificate with new one. I can't find any difference in subject name, domain name, purpose, etc. Public / Private keys are different.

It should work....but it doesn't. Any thoughts?

Microsoft Entra
0 comments No comments
{count} votes

Accepted answer
  1. Marcin Policht 10,845 Reputation points MVP
    2024-04-18T17:48:44.9266667+00:00

    I gather you're following https://learn.microsoft.com/en-us/entra/identity/domain-services/tutorial-configure-ldaps - correct? If so, at which point exactly the procedure described in that article fails - and what's the error message?


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


0 additional answers

Sort by: Most helpful